Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

For GitOps, choose based on where the original secret value should live and how an application should receive it. Sealed Secrets lets you commit encrypted secret manifests to Git; External Secrets Operator (ESO) fetches values from an external provider and synchronizes them into Kubernetes Secrets; Vault is a secret-management platform with several ways to deliver credentials. They solve different parts of the problem, so the right choice depends on your source of truth, rotation needs, tolerance for Kubernetes Secret objects, and ability to operate the required systems.

How do the three approaches differ?

The key distinction is not which product encrypts a file best. It is where the usable value is kept, what Git contains, and what component makes the value available to a workload.

Approach What GitOps configuration contains How values reach Kubernetes workloads Where key operational responsibility sits
Sealed Secrets A SealedSecret containing encrypted secret data and placement constraints. The Sealed Secrets controller decrypts it and creates a native Kubernetes Secret. Protecting and recovering the controller’s private key, plus rotating application credentials and resealing changed values.
External Secrets Operator ExternalSecret references and mappings that describe what to retrieve and where to put it. ESO reads from a configured provider and creates or updates a native Kubernetes Secret. Securing provider credentials, access scope, synchronization permissions, and the resulting Kubernetes Secret.
Vault Configuration depends on the Vault integration and delivery pattern; Vault is the secret platform, not one Kubernetes delivery method. Vault Secrets Operator can synchronize supported values into Kubernetes Secrets. CSI and Agent Injector are other documented integration options. Operating or procuring Vault, protecting its authentication and policies, and securing the chosen workload integration.

This is an architectural comparison, not a universal security ranking. A Sealed Secrets controller, an ESO provider integration, and a Vault deployment introduce different trust boundaries and operational work.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Sealed Secrets protects—and what it does not

Sealed Secrets is useful when a team wants secret manifests to travel through the same Git-based review and deployment workflow as other Kubernetes configuration, without storing the secret values there in readable form. The kubeseal client encrypts the payload; a controller in the target cluster decrypts it.

#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

The Sealed Secrets cryptography documentation describes AES-256-GCM for the payload and RSA-OAEP with SHA-256 to protect a one-time session key. Its default strict scope binds decryption to both the Kubernetes Secret’s name and namespace. Namespace-wide scope binds it to the namespace; cluster-wide scope uses an empty label and is more permissive. Treat broader scopes as an explicit trade-off, not a default convenience.

  • Protect the controller private key. It is needed to decrypt sealed values. Back it up with care: a backup also carries decryption capability. If the key used to seal a resource is lost, the project FAQ says operators may need to recreate the credentials and seal them again.
  • Do not treat encryption as authorization. The project notes that the workflow does not authenticate the person submitting a SealedSecret. Git review, deployment permissions, and Kubernetes RBAC still need to restrict who can change and apply resources.
  • Separate key renewal from credential rotation. The project documentation states: “SealedSecret key renewal and re-encryption features are not a substitute for periodical rotation of your actual secret values.” Changing an encryption key does not change a database password, API token, or certificate. Rotate the credential with its issuer or service, then reseal the new value.

Consider this option if encrypted manifests in Git fit your workflow and your team can manage private-key backup, recovery, and credential resealing. It is a poor fit if the team expects encryption alone to handle access control or application credential lifecycle.

When does External Secrets Operator fit?

ESO suits teams that already keep source values in an external secret provider and want Kubernetes resources to declaratively describe how those values are consumed. An ExternalSecret can map specific provider entries with spec.data or retrieve a broader set through spec.dataFrom. ESO then reconciles the requested values into its configured target Secret.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

That synchronization pattern does not keep plaintext out of the cluster: the resulting object is a Kubernetes Secret and remains subject to Kubernetes access controls and the cluster’s security configuration. Protecting the provider and protecting the synchronized Secret are separate tasks. OWASP’s DevSecOps guidance discusses ESO as a reference to a central store; the actual exposure depends on the deployment and its controls.

Choose refresh behavior deliberately

ESO’s refresh policy determines when it fetches values. Periodic is the default and uses a configurable refresh interval. CreatedOnce creates the target once rather than continuously refreshing it; OnChange responds to changes in the ExternalSecret’s metadata or specification. Under Periodic, a refresh interval of zero creates the target but does not periodically update it.

For a rotating provider value, verify that the selected policy and interval allow the new value to reach the target on the timeline your application requires. Also inspect the chosen provider integration and deletion policy: refresh behavior alone does not describe every consequence of changing or removing a reference.

Rank #3
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

ESO is a strong candidate when an external provider is already the source of truth and automated synchronization is desired. It adds dependencies on provider access, ESO permissions, and the lifecycle of the Kubernetes Secret it creates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do you need Vault for Kubernetes secrets?

Not necessarily. Vault makes sense when you need a centralized secret-management platform or Vault-specific capabilities and can operate or procure that platform. It is broader than a Kubernetes synchronization operator: the way a workload consumes a value depends on the integration selected.

Vault Secrets Operator

Vault Secrets Operator synchronizes supported Vault sources into Kubernetes Secret resources. This can fit applications that already consume native Secrets, but it does not avoid placing the synchronized value in a Kubernetes Secret.

Rank #4
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

CSI and Agent Injector

HashiCorp also documents a Vault Secrets Store CSI provider and Vault Agent Injector. These are alternative delivery paths to consider when avoiding Kubernetes Secret objects is a requirement. Confirm how the chosen integration presents values and whether the application can consume that form; do not assume that every Vault integration avoids native Secrets.

Vault Kubernetes Secrets Engine

The Kubernetes Secrets Engine can generate service-account tokens and, when configured, create service accounts, role bindings, and roles. Its tokens have configurable TTLs, and Kubernetes objects created by the engine are automatically deleted when the Vault lease expires. This behavior applies to that engine’s lease lifecycle; it should not be generalized to every Vault secret type or every Vault Secrets Operator workflow. The engine also requires configuration and appropriate Kubernetes permissions for its Vault service account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose Vault when its centralized platform or a specific Vault capability is part of the requirement, and assign owners for Vault availability, authentication methods, policies, and the Kubernetes integration. If the need is only to synchronize values from an existing provider, ESO may be the more direct pattern; if the need is encrypted manifests in Git, Sealed Secrets addresses that different workflow.

Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should you choose?

  • Choose Sealed Secrets when you want encrypted secret manifests committed with GitOps configuration and can securely manage the controller key lifecycle. Plan how credential changes will be made and resealed.
  • Choose ESO when an external provider already holds source values and you want declarative Kubernetes references with automated synchronization. Decide refresh and deletion behavior, and account for the target Kubernetes Secret.
  • Choose Vault when a centralized secret platform, Vault-managed credentials, or a Vault integration is required and your organization can operate or procure it. Select the delivery path according to whether Kubernetes Secret objects are acceptable.

These choices can also coexist. For example, Vault may be the backend while an integration delivers values to workloads; the question then becomes which delivery mechanism meets the application’s needs and what data is materialized in Kubernetes. Avoid treating product names as mutually exclusive architectures.

Plan rotation, recovery, and access before rollout

Write down the lifecycle for each credential rather than relying on the word “rotation” as a feature checkbox. For each secret, identify who changes the value at its issuer, how the new value reaches the workload, how the application reloads or restarts, and how the prior value is revoked. The appropriate sequence differs for a sealed manifest, an ESO-synchronized value, and a Vault-issued lease.

  • Map the trust boundary. Identify who can read or change Git configuration, access provider values, administer the controller or operator, read Kubernetes Secrets, and alter Vault policy or authentication.
  • Test recovery. For Sealed Secrets, verify the protected private-key backup and recovery procedure. For ESO, verify that provider credentials and permissions can be restored. For Vault, include the platform and selected integration in the recovery plan.
  • Test value change end to end. Confirm that a changed value is fetched or decrypted, reaches the intended workload, and is adopted by the application before the old credential is revoked.
  • Check deletion semantics. Understand what happens to target objects when references or source values are removed, and whether lease expiration applies to the particular engine and credential type in use.
  • Keep permissions scoped. Limit controller, operator, provider, Vault, GitOps, and workload access to the namespaces and resources each actually needs.

Implementation details and supported integrations change across releases. Check the documentation for the versions of Kubernetes, Sealed Secrets, ESO, Vault, and the chosen provider integration you deploy; in particular, verify policy defaults, refresh behavior, and compatibility rather than assuming a mutable “latest” documentation page matches an older cluster.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.