External Secrets Operator (ESO) is the Kubernetes controller for integrating external secret stores (Vault, AWS Secrets Manager, Azure Key Vault) with K8s workloads. At scale, ESO becomes a critical infrastructure component: handling multi-region failover, compliance auditing, zero-downtime rotation, and secret distribution to 1000s of pods. The skill encompasses designing for compliance (SOC2, HIPAA, PCI), scaling to petabyte-scale secrets, multi-cloud federation, and incident response (rapid rotation on breach). This is infrastructure engineering, not just "sync secrets to K8s."