Managing secrets in Kubernetes gets complicated fast.
In this video, we cover the core patterns teams use in production — native Secrets + ConfigMaps, Sealed Secrets, External Secrets Operator, CSI, and agent injection — plus how centralized platforms like Infisical fit into modern workflows.
You’ll learn the mental models behind each approach, the tradeoffs they introduce, and how teams typically evolve from basic Kubernetes secrets to external, centralized systems using tools like External Secrets Operator.
If you’re running apps on Kubernetes and dealing with API keys, DB creds, or tokens, this will save you a ton of future pain.
Timestamps
0:00 – Why secrets management gets hard in Kubernetes
1:00 – ConfigMaps vs Secrets (what Kubernetes gives you)
2:40 – Demo: injecting secrets into a Kubernetes app
4:10 – Why native secrets break down at scale
5:00 – Sealed Secrets & GitOps (encrypting secrets for Git)
7:20 – External Secrets Operator (ESO) & centralized secret stores
9:15 – CSI pattern: mounting secrets without storing them in Kubernetes
10:45 – Agent injection vs CSI + final architecture tradeoffs
🔗 References & Resources
Infisical (GitHub) — https://github.com/Infisical/infisical
Infisical Kubernetes Operator docs — https://infisical.com/docs/integratio...
Infisical Kubernetes CSI docs — https://infisical.com/docs/integratio...
Infisical Kubernetes Agent Injector docs — https://infisical.com/docs/integratio...
External Secrets Operator (ESO) — https://external-secrets.io
Bitnami Sealed Secrets (GitHub) — https://github.com/bitnami-labs/seale...
Kubernetes Secrets Store CSI Driver (GitHub) — https://github.com/kubernetes-sigs/se...
Kubernetes Secrets (official docs) — https://kubernetes.io/docs/concepts/c...
Timestamps:
0:00 Intro
Follow Infisical:
Website: https://infisical.com
Linkedin: / infisical
GitHub: https://github.com/Infisical
Twitter / X: https://x.com/infisical
Slack: https://infisical.com/slack