Session
Stop Writing Secrets Into YAML: A Rotation-First Identity Pattern for Kubernetes
The goal is not to hide long-lived credentials better; it is to need fewer of them, issue them later, and rotate them automatically. Kubernetes already warns that Secrets are stored unencrypted in etcd by default unless protections are added, that anyone with API or etcd access may retrieve them, and that users who can create Pods in a namespace can often read Secrets there indirectly. The platform has also moved away from older long-lived service-account token Secrets toward projected tokens obtained through the TokenRequest
API. This session turns those warnings into an architecture and migration guide: use projected serviceaccount tokens where they fit, adopt workload identity through SPIFFE/SPIRE, and bring in OpenBao when dynamic secrets, leases, and automatic revocation are needed. Rather than presenting a vendor parade, the talk shows where each layer belongs, how to reduce “secret zero” risk, and how to move from static
credentials toward short-lived, auditable access.
Fabrizio Sgura
Chief Engineer (Platform Product Business, Distributed Architecture) at Veritas Automata|CNCF Ambassador|Golden Kubestronaut
Panamá, Panama
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top