Secrets Strategy

Choosing a Secrets Strategy for BookNest

Ways to get secrets into a cluster (all open source)
Approach Value lives in Rotation Best for
Plain Secret, created by hand The cluster only Manual Labs and one-off clusters
Sealed Secrets 9,292 or SOPS 23,231 Git 1,932 , encrypted Re-seal and commit GitOps without a secret manager
External Secrets Operator 82,285 A secret manager Automatic sync Several clusters, cloud accounts
Secrets Store CSI Driver A secret manager On remount Values that must never become Secrets

BookNest uses both main paths: values it owns and rarely changes, such as the backup credentials, travel in Git as SealedSecrets so Argo CD 126 (GitOps with Argo CD) can deploy everything; the production database password belongs in a cloud secret manager behind ESO. Either way, keep get secrets out of pipeline roles and rotate leaked values.