Project reference ↗

Teams managing deployments in Git need a way to include credentials without committing their readable values. Sealed Secrets encrypts a Secret into a sealed manifest; a controller with the corresponding private key decrypts it and creates the Kubernetes Secret. This lets encrypted configuration travel through the same review process as other manifests. The private keys remain essential recovery material, and rotating those encryption keys is separate from changing the actual passwords or tokens used by applications.

Current guidance

This entry identifies the Bitnami Sealed Secrets project: kubeseal encrypts data for a controller that creates Kubernetes Secrets. The current upstream documentation distinguishes chart versions from application versions and explains strict, namespace-wide and cluster-wide sealing scopes. Choose the narrowest scope that fits the deployment; the default binding to a Secret name and namespace is a meaningful protection.

The controller’s private sealing keys are essential recovery material. Keeping encrypted manifests in Git does not make them recoverable after losing every applicable private key. Back up keys securely, limit access and rehearse restoring them into an isolated environment. Treat the decrypted Kubernetes Secret as sensitive data subject to cluster RBAC and storage protections.

Key renewal and re-encryption are different from changing a database password or revoking an API token. Define application credential rotation separately, including how workloads reload new values. When moving between clusters or replacing the controller, test old ciphertext recovery and namespace/name behavior before removing keys. This is an encryption delivery pattern, not a complete external secret store or an automatic rotation service.

Historical upstream link check · 2026-10-09

The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub confirms that helm/charts is archived: this is a historical chart distribution, not evidence that the application itself is retired. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Original publication: 2018-12-22T08:33:42+00:00. Preserved for context. Commands, versions, prices and results below reflect the original research.

Problem: “I can manage all my K8s config in git, except Secrets.”

Solution: Encrypt your Secret into a SealedSecret, which is safe to store – even to a public repository. The SealedSecret can be decrypted only by the controller running in the target cluster and nobody else (not even the original author) is able to obtain the original Secret from the SealedSecret.

The post sealed secrets appeared first on kubedex.com.

Sources & further reading

  1. Sealed Secrets scopes, key management and recovery
  2. Canonical Sealed Secrets project and official chart
  3. Recovered historical source

Spotted something that needs another look?

Help improve this page →