GitLab Secrets Manager adds ESO, Terraform, API support
Blog post from GitLab
GitLab Secrets Manager, powered by OpenBao, is expanding beyond CI/CD to serve as a centralized secret store for Kubernetes workloads, Terraform or OpenTofu, Vault-compatible command-line tools, and external automation APIs. Kubernetes integrations use External Secrets Operator with short-lived GitLab-minted JWTs to authenticate, retrieve secrets through GitLab’s Vault-compatible KV v2 API, and periodically synchronize them into Kubernetes Secrets, allowing rotated credentials to propagate without redeployment. Terraform and OpenTofu can retrieve secrets dynamically at plan or apply time through JWT authentication, reducing the risk of credentials being stored in state-adjacent files, variables, or version control. Existing OpenBao and Vault CLI workflows can access GitLab-managed secrets through compatible authentication and retrieval commands, while the Secrets Manager API supports other automated systems. The feature is in public beta for GitLab Premium and Ultimate customers on GitLab.com and GitLab Self-Managed, is free during beta, and is expected to become a paid GitLab Credits feature at general availability.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 59 | 584 | 99 | 52 | -76% |
| Kubernetes | 9 | 634 | 79 | 44 | -75% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.