# Kubernetes secrets

Published articles for Kubernetes secrets.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Managing Environment Variables and Secrets in DevOps

DevFeed: [Managing Environment Variables and Secrets in DevOps](<https://devfeed.tech/articles/managing-environment-variables-and-secrets-in-devops-17486.md>)

Original publisher: [Read original article](<https://kodekloud.com/blog/managing-environment-variables-and-secrets-devops/>)

Author: Pramodh Kumar M

Published: 2026-08-01T13:00:47Z

Content type: tutorial

Language: en

Sources: [Kubernetes - KodeKloud Blog | DevOps, Cloud, Kubernetes, AI Tutorials & More](<https://devfeed.tech/sources/kubernetes-kodekloud-blog-devops-cloud-kubernetes-ai-tutorials-more.md>)

Topics: [DevOps](<https://devfeed.tech/topics/devops.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [GitGuardian](<https://devfeed.tech/topics/gitguardian.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [ci-cd-secrets-management](<https://devfeed.tech/tags/ci-cd-secrets-management.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [collaboration-tools](<https://devfeed.tech/tags/collaboration-tools.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [container](<https://devfeed.tech/tags/container.md>), [crash](<https://devfeed.tech/tags/crash.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [dynamic-secrets](<https://devfeed.tech/tags/dynamic-secrets.md>), [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [environment-variables](<https://devfeed.tech/tags/environment-variables.md>), [gitguardian](<https://devfeed.tech/tags/gitguardian.md>), [github](<https://devfeed.tech/tags/github.md>), [hardcoded-credentials](<https://devfeed.tech/tags/hardcoded-credentials.md>), [hashicorp-vault](<https://devfeed.tech/tags/hashicorp-vault.md>), [jira](<https://devfeed.tech/tags/jira.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-secrets](<https://devfeed.tech/tags/kubernetes-secrets.md>), [leak](<https://devfeed.tech/tags/leak.md>), [managing-environment-variables-and-secrets](<https://devfeed.tech/tags/managing-environment-variables-and-secrets.md>), [rotation](<https://devfeed.tech/tags/rotation.md>), [safety](<https://devfeed.tech/tags/safety.md>), [sealed-secrets](<https://devfeed.tech/tags/sealed-secrets.md>), [secret-rotation](<https://devfeed.tech/tags/secret-rotation.md>), [secret-scanning](<https://devfeed.tech/tags/secret-scanning.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [secrets-management-best-practices](<https://devfeed.tech/tags/secrets-management-best-practices.md>), [security](<https://devfeed.tech/tags/security.md>), [storage](<https://devfeed.tech/tags/storage.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [vault](<https://devfeed.tech/tags/vault.md>)

### AI overview

A guide to managing environment variables and secrets in DevOps. It explains how secrets escape through repositories, processes, crash reports, containers, collaboration tools, Kubernetes Secrets, and Terraform state, and discusses storage, access controls, lifecycles, and rotation.

### Source excerpt

Nearly 29 million secrets were pushed to public GitHub in a single year, and most teams still discover their own leaks by accident. Here is how environment variables actually escape, and what to use instead at each stage.

## Kubernetes Secrets and ConfigMaps in 2026: the Secret is the last mile " Giant Swarm

DevFeed: [Kubernetes Secrets and ConfigMaps in 2026: the Secret is the last mile " Giant Swarm](<https://devfeed.tech/articles/kubernetes-secrets-and-configmaps-in-2026-the-secret-is-the-last-mile-giant-swarm-17496.md>)

Original publisher: [Read original article](<https://www.giantswarm.io/blog/kubernetes-secrets-and-configmaps-in-2026-the-secret-is-the-last-mile>)

Author: Puja Abbassi

Published: 2026-06-29T10:31:16Z

Content type: tutorial

Language: en

Sources: [Giant Swarm Blog](<https://devfeed.tech/sources/giant-swarm-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [configuration](<https://devfeed.tech/tags/configuration.md>), [containers](<https://devfeed.tech/tags/containers.md>), [dev](<https://devfeed.tech/tags/dev.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-secrets](<https://devfeed.tech/tags/kubernetes-secrets.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [tech](<https://devfeed.tech/tags/tech.md>)

### AI overview

This tutorial revisits Kubernetes Secrets and ConfigMaps and explains how their role fits into a longer production pipeline in 2026. It covers their purpose, scope, delivery methods, size and update behavior, including the need to restart workloads after Secret changes.

### Source excerpt

Part IV of the Understanding Basic Kubernetes Concepts series, updated from the 2016 original.

## Join Teleport at KubeCon + CloudNativeCon Europe 2024

DevFeed: [Join Teleport at KubeCon + CloudNativeCon Europe 2024](<https://devfeed.tech/articles/join-teleport-at-kubecon-cloudnativecon-europe-2024-29731.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/kubecon-eu-2024/>)

Author: david.sudia@goteleport.com (Dave Sudia)

Published: 2024-03-13T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>)

Tags: [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [identity](<https://devfeed.tech/tags/identity.md>), [kubecon-eu](<https://devfeed.tech/tags/kubecon-eu.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-secrets](<https://devfeed.tech/tags/kubernetes-secrets.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Teleport's KubeCon + CloudNativeCon Europe 2024 message presents a Zero Trust platform for unified identity, access, and policy management across Cloud Native infrastructure. The article highlights single-login access, short-lived privileges, Just-in-Time Access, and the rollout of Workload Identity.

### Source excerpt

Come find out how Teleport provides security for Cloud Native technologies.

## The Birth of the External Secrets Community

DevFeed: [The Birth of the External Secrets Community](<https://devfeed.tech/articles/the-birth-of-the-external-secrets-community-17696.md>)

Original publisher: [Read original article](<https://blog.container-solutions.com/the-birth-of-the-external-secrets-community>)

Author: Lucas Severo Alves

Published: 2021-05-06T07:12:38Z

Content type: article

Language: en

Sources: [Blog - Container Solutions](<https://devfeed.tech/sources/blog-container-solutions.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [google-cloud](<https://devfeed.tech/tags/google-cloud.md>), [hashicorp-vault](<https://devfeed.tech/tags/hashicorp-vault.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-secrets](<https://devfeed.tech/tags/kubernetes-secrets.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secret-rotation](<https://devfeed.tech/tags/secret-rotation.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article describes the growth of projects that synchronize secrets from external providers into Kubernetes and the formation of a community around the External Secrets Operator. It highlights GoDaddy's kubernetes-external-secrets project, its provider integrations and active maintenance, while noting that it was developed in JavaScript.

### Source excerpt

Managing secrets in Kubernetes can be a cumbersome job. In a multi-service multi-environment setup, you can end up with hundreds of secrets without even noticing. It is hard to keep track of everything and at the same time manage secret rotation, onboard new services, and onboard new people with correct access permissions.

## What's Coming To Keycloak

DevFeed: [What's Coming To Keycloak](<https://devfeed.tech/articles/what-s-coming-to-keycloak-31579.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2019/09/2019-roadmap>)

Author: Stian Thorgersen

Published: 2019-09-03T00:00:00Z

Content type: opinion

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [account](<https://devfeed.tech/topics/account.md>), [React](<https://devfeed.tech/topics/react.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Operator Lifecycle Manager](<https://devfeed.tech/topics/olm.md>), [API](<https://devfeed.tech/topics/api.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [health checks](<https://devfeed.tech/topics/health-checks.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [automated](<https://devfeed.tech/tags/automated.md>), [console](<https://devfeed.tech/tags/console.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [health-checks](<https://devfeed.tech/tags/health-checks.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-secrets](<https://devfeed.tech/tags/kubernetes-secrets.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [operator](<https://devfeed.tech/tags/operator.md>), [password](<https://devfeed.tech/tags/password.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>), [saml](<https://devfeed.tech/tags/saml.md>), [software](<https://devfeed.tech/tags/software.md>), [sso](<https://devfeed.tech/tags/sso.md>), [usability](<https://devfeed.tech/tags/usability.md>), [user-experience](<https://devfeed.tech/tags/user-experience.md>), [vault](<https://devfeed.tech/tags/vault.md>)

### AI overview

Keycloak's 2019 roadmap outlines planned work on a new React-based account console, WebAuthn authentication, a Kubernetes operator, external vault integration, user profiles, metrics and health checks, and improved automated testing and builds.

### Source excerpt

New Account Console and Account REST API The current account console is getting dated. It is also having issues around usability and being hard to extend. For this reason we had the UXD team at Red Hat develop wireframes for a new account console. The new console is being implemented with React.js providing a better user experience as well as making it easier to extend and customise. JIRA - Account Console JIRA - Account REST API WebAuthn We are working towards adding WebAuthn support both for two factor authentication and passwordless experience. This task is not as simple as adding an authenticator for WebAuth, but will also require work on improving authentication flows and the account console. Design proposal - Authentication flow improvements Design proposal - WebAuthn Authenticator Design proposal - WebAuthn Two factor JIRA - Two factor JIRA - Passwordless Operator Operators are becoming an important way to manage software running on Kubernetes and we are working on an operator for Keycloak. The aim is to have an operator published on OperatorHub.io soon which provides basic install and seamless upgrade capabilities. This will be based on the awesome work done by the Red Hat Integreatly team. JIRA Integreatly Keycloak Operator Vault At the moment to keep credentials such as LDAP bind credentials more secure it is required to encrypt the whole database. This can be complex and can also have a performance overhead. We are working towards enabling loading credentials, such as LDAP bind credential and SMTP password, from an external vault. We're providing a built-in integration with Kubernetes secrets as well as an SPI allowing integrating with any vault provider. In the future we will also provide the option to encrypt other more dynamic credentials at rest in the database. JIRA - Vault JIRA - Encryption at rest User Profile Currently there's no single place to define user profiles for a realm. To resolve this we are planning to introduce the Profile SPI, which w