Skip to main content
Safely encrypt your Kubernetes Secrets using the Sealed Secrets Operator. This guide walks you through installing the operator via Helm, fetching its public key, and sealing a Secret.
  • Helm 3.x installed
  • kubectl configured with access to your target cluster
  • Cluster-admin privileges (or equivalent)

1. Add the Sealed-Secrets Helm Repository

Register the Bitnami Sealed Secrets chart and update your local repo cache:

2. Install the Sealed-Secrets Chart

Choose between installing into the default namespace or a custom namespace.

3. Verify the Operator Pod

Confirm that the Sealed Secrets controller is running: You should see a pod like my-release-sealed-secrets-controller-<id> in Running status.

4. Fetch the Controller’s Public Key

Download the operator’s certificate to seal Secrets locally. Replace <release-name> and <namespace> as needed:
If you installed into the default namespace, omit --controller-namespace or set it to default.

5. Create and Seal a Secret

  1. Generate a Kubernetes Secret manifest (client-side dry run):
  2. Seal the Secret using the fetched certificate:
  3. Apply the SealedSecret to your cluster:

6. Confirm Deployment

Ensure the Sealed Secrets Operator is still running after sealing: Once verified, your Sealed Secrets Operator is ready to encrypt and manage Kubernetes Secrets securely!

Watch Video