@kodekloud: Stop Storing Kubernetes Secrets Like This! ⚠️ Standard Kubernetes Secrets are only Base64-encoded and sit unencrypted in etcd by default. If developers dump environment variables to debug an issue, sensitive Stripe keys end up readable by anyone in logging tools like Datadog! Here are two ways to secure your microservices: 1. Lock Down K8s: Enable encryption at rest with KMS, restrict namespace access, and lock down RBAC. 2. Zero Trust with HashiCorp Vault: Move keys out of etcd entirely. Use Vault Agents and service account tokens to read secrets directly from shared memory volumes with full audit logging. #Kubernetes #DevOps #HashiCorpVault #CyberSecurity #CloudNative #Shorts
bitnami sealed secrets is great as well, just need to keep the controller key secure. with it you can store the encrypted secret file in git along with your other manifest files.
2026-09-29 22:07:05
0
ForgottenTrickster :
Where do I keep the secret of the service account? O they don't use one? I'm asking from ignorance.
2026-09-29 16:16:09
0
someonefromthere1 :
just on time.. thank you for the great explanation
2026-09-29 15:12:45
0
maxpayne :
Oenbao is a useful option not mentioned a lot.
2026-09-29 20:20:06
0
Gerry :
encrypted log writer?
2026-09-29 19:26:57
0
Foxilsupergenio96 Fo :
this videos are Absolute gold
2026-09-29 14:46:51
3
azrael :
I used Google Secret Manager
2026-09-29 16:27:27
1
Maximus :
Akeyless is probably the best way of managing secrets, it independently generates fragments of the key which are held in separate, encrypted datastores across cloud providers and regions. After authorisation, each fragment produces a value and provides it to the pod.
2026-09-29 15:18:39
1
jjkar404 :
Wow 💯💯
2026-09-29 13:31:25
0
Jawaid Iqbal :
we keep a secret in the vault and inject
2026-09-29 18:59:54
0
SookMaPlooms :
👌👌👌
2026-09-30 00:32:02
0
To see more videos from user @kodekloud, please go to the Tikwm
homepage.