Spotlight

Building Secure GitOps Pipelines: Integrating External Secrets Operator with ArgoCD on EKS

Josh Woolbright

This tutorial shows how to secure an ArgoCD based EKS GitOps workflow with External Secrets Operator, IRSA, and AWS SSM Parameter Store so secrets stay out of Git and sync safely into Kubernetes.

More articles →

Tools and utilities

  • Trupositive

    Trupositive is a wrapper that automatically tags Terraform and CloudFormation resources with Git commit SHA, branch, and repository metadata for auditability and infrastructure traceability.

  • Warden for Identity-Based Access Control for AI Agents and Kubernetes Workloads

    Warden is an open source runtime access gateway that lets AI agents, pods, pipelines, and services use identity-based policies to reach cloud APIs, databases, and storage without storing long-lived credentials.

  • SOPS Operator: secrets management

    This tool runs inside Kubernetes and automatically decrypts secrets encrypted with Mozilla SOPS, and then creates standard Kubernetes Secret objects from them.

  • Siclaw

    Siclaw is an open source AI SRE platform for read-only infrastructure diagnostics, root cause analysis, team workflows, Kubernetes access, and MCP-based investigation without changing live systems directly.

  • PII-Shield

    PII-Shield is a sidecar that sanitizes logs before they leave the pod by detecting secrets and personal data, preserving JSON structure, and supporting Helm based deployment..

More projects →

Events starting soon

Discover more events onn Kube Events →

Subscribe to Learn Kubernetes Weekly

Trusted by 77K engineers. Delivered 150 issues and counting.

or subscribe via

Learn from production

More case studies →

Matching jobs

    • DevOps Engineer with Epic Kids Inc.

    • Salary: $90 to $484K a year

    • Location: remote from

    • Tech stack: Kubernetes, GCP, Helm, ArgoCD, Docker, Python, Airflow, Terraform, GitHub Actions, Jenkins

    • DevOps Engineer with Prime Intellect

    • Salary: $150K to $300K a year

    • Location: based in the office (and remote from home) in San Francisco, CA, USA

    • Tech stack: Kubernetes, GCP, Go, Python, Rust, Typescript, Terraform, Ansible, Grafana, Prometheus

    • DevOps Engineer with TMS LLC

    • Salary: $85 a day

    • Location: remote from

    • Tech stack: Kubernetes, Azure, Terraform, Azure DevOps

    • DevSecOps Engineer with CHAOS Industries

    • Salary: $140K to $220K a year

    • Location: based in the office in Hawthorne, CA, USA

    • Tech stack: Kubernetes, Azure, On-premise, Docker, C++, Go, Java, Python, Rust, Azure DevOps

    • DevSecOps Engineer with PactFi

    • Salary: $12.6K to $445.5K a year

    • Location: based in the office in New York, NY, USA

    • Tech stack: Kubernetes, AWS, Docker, Python, Redis, Pulumi, Terraform, Jenkins

Discover more Kubernetes jobs on Kube Careers →

Thanks to our sponsors who make Kube Today possible

Find out more about being a sponsor →

Build something

More tutorials →

More articles

Even more articles →