A Secret manifest is base64, not encryption, so it cannot go into Git 1,932 , leaving GitOps (GitOps with Argo CD) a hole in every environment. In the cluster, list on Secrets reveals every value in a namespace and anyone who can create a Pod can mount them; rotation is manual and each cluster holds its own copy. The fixes either encrypt the value so it can live in Git (Sealed Secrets 9,292 , SOPS 23,231 ) or keep it in a secret manager and sync it in (External Secrets Operator 82,285 , the Secrets Store CSI Driver).
MENU
Secrets' Limits
Why Kubernetes Secrets Alone Are Not Enough