SOPS and age Secret Workflow
A safe workflow for encrypting Kubernetes Secrets in Git and allowing Flux to decrypt them during reconciliation.
Open Runbook entryRunbook category
Flux, Kustomize and SOPS references for validation, reconciliation, application delivery and troubleshooting.
Flux, Kustomize and SOPS references for validating and operating Git-managed Kubernetes environments.
The collection covers reconciliation, controller health, repository structure, application onboarding, rendering, dry runs, drift investigation and encrypted secrets.
Manual reconciliation is clearly identified because it may change Kubernetes resources. ``
Technical reference
Commands, checks, troubleshooting procedures and operational references for this subject.
A safe workflow for encrypting Kubernetes Secrets in Git and allowing Flux to decrypt them during reconciliation.
Open Runbook entryValidate desired-state manifests locally and against the Kubernetes API without persisting changes.
Open Runbook entryA reusable repository layout for separating cluster registration, applications, infrastructure, monitoring, networking, security and operational documentation.
Open Runbook entryCompare Git, Flux revisions and live Kubernetes resources when desired and actual state differ.
Open Runbook entryCommands for checking Flux health, inspecting GitOps resources, triggering reconciliation and troubleshooting failed deployments.
Open Runbook entryFocused checks for Flux Kustomization build failures, dependencies, health checks, revisions and applied resources.
Open Runbook entryRead-only checks for Flux controllers, sources, reconciliation status, events and controller logs.
Open Runbook entryPlan, render, validate and reconcile a Kubernetes application through Flux GitOps.
Open Runbook entry