You need secrets in Git for GitOps. But plaintext secrets in Git are a breach waiting to happen. SOPS encrypts only the values, leaving the keys readable — so you can review diffs, grep for key names, and still keep values secret.
How SOPS Works
# Before encryption (plaintext)
database:
host: db.internal.myorg.com
username: app_user
password: s3cur3-p@ssw0rd
port: 5432
# After encryption (SOPS)
database:
host: ENC[AES256_GCM,data:abc123...,type:str]
username: ENC[AES256_GCM,data:def456...,type:str]
password: ENC[AES256_GCM,data:ghi789...,type:str]
port: 5432 # integers not encrypted by defaultKeys stay readable. Values are encrypted. You can see the structure without seeing the secrets.
Setup with age
age is the simplest key management option:
# Install
brew install sops age
# Generate a key pair
age-keygen -o ~/.sops/age-key.txt
# Public key: age1abc123...
# Create .sops.yaml config
cat > .sops.yaml <<EOF
creation_rules:
- path_regex: .*\.enc\.yaml$
age: age1abc123...
EOFEncrypt and Decrypt
# Encrypt a file
sops encrypt secrets.yaml > secrets.enc.yaml
# Decrypt
sops decrypt secrets.enc.yaml > secrets.yaml
# Edit encrypted file in-place (opens $EDITOR)
sops secrets.enc.yamlWhen you run sops secrets.enc.yaml, it decrypts to a temp file, opens your editor, and re-encrypts on save.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →AWS KMS
# .sops.yaml
creation_rules:
- path_regex: production/.*\.enc\.yaml$
kms: arn:aws:kms:eu-west-1:123456789:key/abc-def-123
- path_regex: staging/.*\.enc\.yaml$
kms: arn:aws:kms:eu-west-1:123456789:key/xyz-789-456Different KMS keys for different environments. Production secrets can only be decrypted by production IAM roles.
Multiple Recipients
creation_rules:
- path_regex: .*\.enc\.yaml$
age: >-
age1alice...,
age1bob...,
age1ci-server...Alice, Bob, and the CI server can all decrypt. Remove someone's key and re-encrypt to revoke access.
Git Diff
# Normal git diff shows meaningful changes:
database:
- host: ENC[AES256_GCM,data:old_encrypted_host...]
+ host: ENC[AES256_GCM,data:new_encrypted_host...]
username: ENC[AES256_GCM,data:unchanged...]
+ replica_host: ENC[AES256_GCM,data:new_field...]You can see that host changed and replica_host was added — without seeing the values.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Kubernetes Integration
Flux + SOPS
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: app-secrets
spec:
decryption:
provider: sops
secretRef:
name: sops-age-keyFlux decrypts SOPS files during reconciliation. Encrypted secrets in Git, decrypted in cluster.
Helm + SOPS
# Encrypt Helm values
sops encrypt values-secret.yaml > values-secret.enc.yaml
# Use helm-secrets plugin
helm secrets install myapp ./chart \
-f values.yaml \
-f values-secret.enc.yamlCI/CD Integration
# GitHub Actions
- name: Decrypt secrets
run: |
sops decrypt secrets.enc.yaml > secrets.yaml
env:
SOPS_AGE_KEY: ${{ secrets.SOPS_AGE_KEY }}Store the age private key (or AWS/GCP credentials) in CI secrets. SOPS decrypts during the pipeline.
.sops.yaml Patterns
creation_rules:
# Encrypt everything except 'metadata' and 'kind'
- path_regex: k8s/.*\.enc\.yaml$
encrypted_regex: "^(data|stringData)$"
age: age1abc...
# Only encrypt specific keys in app config
- path_regex: config/.*\.enc\.yaml$
encrypted_regex: "^(password|secret|token|key)$"
age: age1abc...SOPS vs Alternatives
| Feature | SOPS | Sealed Secrets | Vault | git-crypt |
|---|---|---|---|---|
| Encrypted in Git | Yes | Yes | No | Yes |
| Key management | age/KMS | Cluster key | Vault server | GPG |
| Partial encryption | Values only | Whole secret | N/A | Whole file |
| Diff-friendly | Yes | No | N/A | No |
| Kubernetes native | Via Flux | Yes | Via agent | No |
| Multi-cloud KMS | Yes | No | Yes | No |
Use SOPS for GitOps workflows where you want encrypted secrets in Git with readable diffs. Use External Secrets when you have a central secrets manager. Use Sealed Secrets for the simplest Kubernetes-only approach.
---
Ready to go deeper? Master secrets management with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Sealed Secrets Kubernetes Guide
Sealed Secrets encrypts Kubernetes secrets so you can store them safely in Git. Learn how to install Sealed Secrets, encrypt secrets, and manage key rotation.
Ansible Vault: Encrypt Secrets Safely
Learn Ansible Vault to encrypt passwords, API keys, and variables. Covers vault create, edit, encrypt_string, and CI/CD usage.
Vault Secrets Management Guide
Manage secrets with HashiCorp Vault. KV engine, dynamic credentials, auth methods, policies, and Kubernetes integration patterns.
Spacelift Terraform Orchestration
Spacelift orchestrates Terraform, OpenTofu, and Pulumi with policies, drift detection, and approval workflows. Learn how Spacelift compares to Terraform Cloud.
Spatial Computing for Enterprise
Deploy spatial computing applications with AR/VR infrastructure, 3D content pipelines, and edge computing for enterprise digital twin visualizations.
SRE Golden Signals Monitoring
Implement SRE golden signals. Latency, traffic, errors, and saturation dashboards with Prometheus queries and Grafana visualizations.
Explore topics
Browse more articles on the topics covered here.