| Approach | Value lives in | Rotation | Best for |
|---|---|---|---|
| Plain Secret, created by hand | The cluster only | Manual | Labs and one-off clusters |
| Sealed Secrets 9,292 or SOPS 23,231 | Git 1,932 , encrypted | Re-seal and commit | GitOps without a secret manager |
| External Secrets Operator 82,285 | A secret manager | Automatic sync | Several clusters, cloud accounts |
| Secrets Store CSI Driver | A secret manager | On remount | Values that must never become Secrets |
BookNest uses both main paths: values it owns and rarely changes, such as the backup credentials, travel in Git as SealedSecrets so Argo CD 126 (GitOps with Argo CD) can deploy everything; the production database password belongs in a cloud secret manager behind ESO. Either way, keep get secrets out of pipeline roles and rotate leaked values.