bitnami/sealed-secrets
A Kubernetes controller and tool for one-way encrypted Secrets observed · 2026-08-28
Health v2 · maintenance only
99/100
- Activity 99
- Release rhythm 98
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 0
- age_days: 3383
- days_rel: 13
- days_push: 8
- n_releases_24m: 50
Adoption not part of the score
9256 stars · 771 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
A Kubernetes controller plus the kubeseal CLI that lets you encrypt Kubernetes Secrets into one-way encrypted SealedSecrets that are safe to commit to Git, even public repositories. Only the controller running in the target cluster can decrypt them, enabling GitOps workflows for secrets.
Use cases
- store kubernetes secrets safely in git
- encrypt secrets for gitops workflows
- commit secrets to a public repository without leaking them
- manage k8s secrets declaratively with helm or kustomize
- rotate or update encrypted secrets in a git repo
- decrypt secrets only inside a target cluster
When to choose
- you practice GitOps and want secrets version-controlled in git
- you need one-way encryption where only the cluster can decrypt
- you use Helm or Kustomize and want secrets as part of your manifests
- you want to avoid external secret managers for simple use cases
When to avoid
- you need multi-cluster or team-wide secret sharing with fine-grained access control
- you require dynamic secret generation or rotation from a vault
- you are not using Kubernetes
- you need to recover the original secret outside the target cluster
Facets
cli-tool · maturity active
secrets-management cryptography deployment infrastructure-as-code cli security cloud-computing infrastructure-as-code self-hosted go windows cloud self-hosted kubernetes gitops sealed-secrets kubeseal kubernetes-controller secret-encryption bitnami devops containers linux macos docker
1 source
- readme: https://github.com/bitnami/sealed-secrets · fetched 2026-08-28 · d1cd5f8c08b0
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| bitnami/sealed-secrets | main | 99 |
For agents
markdown · JSON · MCP: product_card(name="bitnami/sealed-secrets")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem