Session

Why Secrets Belong in Git

Encrypted secrets that is! The audience will learn about tools and techniques that will enable them to version control secrets alongside the code these secrets belong to. Learn how to make them available to agents and LLM tools without bringing them into context. Easily share secrets with new team members and get a full audit log as a bonus. All while following modern security practices.

The session will introduce SOPS and how attendees can use keys stored in secure remote services to encrypt and decrypt files. Access is easily controlled through the same identity providers they use for other services. We will look into how this fits into GitOps practices and how it compares to other common ways of handling secrets in Kubernetes like the External Secrets Operator.

The last thing we want is agents and LLMs reading our secret values into context and sending them to someone else's computer. I will show practical patterns like `sops exec-env`, `sops exec-file` and stdin-based handoff that let agents use secrets without dragging the plaintext into prompts, logs, chats or onto remote servers. The presentation will cover some gotchas to be aware of, but there's no need to be afraid of putting secrets in Git.

Nikolai Norman Andersen

CTO at Variant Oslo

Oslo, Norway

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top