Use Mozilla SOPS with GitOps for encrypted Kubernetes Secrets
How I keep encrypted secret values in Git without turning the repo into a password dump.
Categories
A publication-style index for cloud, web, iOS, travel, and other notes. Tags stay one layer deeper so the archive can grow without crowding the main reading path.
Category
Infrastructure, Kubernetes, data platforms, and backend operations.
How I keep encrypted secret values in Git without turning the repo into a password dump.
How I enroll workloads into ambient mesh and add service-scoped L7 waypoints.
How I keep Airflow Helm values in Git while runtime Secrets come from Vault.
How I sync Vault KV data into Kubernetes Secrets without committing secret values to Git.
A Docker Compose observability backend for metrics, logs, and traces from Kubernetes apps.
How I route public domains through an Istio-managed Gateway and HTTPRoute.
The checklist I use before Argo CD can safely take over a Kubernetes cluster.
A practical GitOps bootstrap flow for my RKE-based home Kubernetes infrastructure.
A short deployment note for running Apache Airflow on top of a Kubernetes cluster.
Use Rancher Kubernetes Engine to build a configurable Kubernetes cluster with Docker-based components.
Use an NFS provisioner to provide persistent storage for a private Kubernetes cluster.
A practical walkthrough for creating a private Kubernetes cluster with kubeadm.
Host a static website for free with GitHub Pages, a custom domain, and Cloudflare DNS.
A DNS over HTTPS and DNS over TLS app for iOS and macOS.