Home / Companies / Octopus Deploy / Blog / Post Details
Content Deep Dive

Securing your GitOps secrets with the Secret Store CSI driver

Blog post from Octopus Deploy

Post Details
Company
Date Published
Author
Kostis Kapelonis
Word Count
1,894
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

Kostis Kapelonis explores the shift to using external secret controllers for managing application secrets within the GitOps paradigm using Argo CD, particularly emphasizing the advantages of the Secret Store CSI driver. With the release of Argo CD v3.x, there is a clear recommendation to use external secret solutions instead of those tied directly to Argo CD's manifest generation process. The Secret Store CSI driver offers a significant benefit by directly mounting secrets as files on pods without using Kubernetes secrets, aligning with certain security policies that prefer avoiding Kubernetes secrets entirely. This approach allows for seamless secret rotation without requiring application redeployments or Argo CD sync operations. The post also includes a demonstration using HashiCorp Vault to manage secrets within a Kubernetes cluster, showcasing how the CSI driver can facilitate secure and efficient secret handling.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 71 2,515 393 134 +17%
Kubernetes 20 2,168 322 107 +10%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.