Skip to main content

Secrets

SOPS and age Secret Workflow

Time guide Validate an existing encrypted Secret: approximately 5 to 10 minutes Create and reconcile a new encrypted Secret: approximately 15 to 30 minutes Investigate a decryption fault: approximately 20 to 45 minutes Purpose # This entry describes a safe workflow for storing encrypted Kubernetes Secret manifests in Git using SOPS and age, with Flux performing decryption during reconciliation.