Part 3 · 2 chapters · ~12 min
Cloud Secret Managers and Kubernetes
AWS Secrets Manager, GCP Secret Manager and Azure Key Vault, KMS and envelope encryption, Kubernetes Secrets and etcd encryption, External Secrets Operator, the Secrets Store CSI driver, Sealed Secrets and SOPS for GitOps, and environment variables against mounted files.
6
Managers, KMS and envelope encryption
| service | notes |
|---|---|
| AWS Secrets Manager | versioned secrets, built-in rotation Lambdas for RDS, IAM-scoped access; Parameter Store for cheaper non-secret config |
| GCP Secret Manager | versioned, IAM per secret, regional replication policies |
| Azure Key Vault | secrets, keys and certificates; managed HSM tier |
| KMS (all clouds) | keys that never leave the service; you send data or data keys to be encrypted |
code
envelope encryption 1 ask KMS for a data key → plaintext DEK + DEK encrypted under the KMS key (KEK) 2 encrypt the data locally with the plaintext DEK (AES-GCM), then discard the plaintext DEK 3 store ciphertext + encrypted DEK together 4 to decrypt: send the encrypted DEK to KMS → plaintext DEK → decrypt locally rotation of the KEK means re-encrypting small DEKs, not terabytes of data
7
Getting secrets into pods
SECRETS INTO KUBERNETES
four common ways a secret reaches a pod, and what each protects
swipe the figure sideways, or tap expand for full screen
1/5
plain k8s Secrets
A Kubernetes Secret is only base64-encoded. Protection depends on etcd encryption at rest (enable it, ideally with a KMS provider), RBAC on who can read Secrets, and never committing them to Git.
base64 is not encryptionenable etcd encryption + strict RBAC