Sealed Secrets is a Kubernetes controller that encrypts secrets with a sealing key (RSA). Secrets are encrypted client-side before committing to Git, then decrypted only on the cluster with the private key. Used by DevOps/SRE teams managing infrastructure-as-code. Salary band: USD 110k–190k. Learn in 4 weeks. Adjacent to Kubernetes secrets, SOPS, Vault.
Sealed Secrets is a Kubernetes controller (from Bitnami) that encrypts Kubernetes secrets before they're stored in Git or etcd. You use the kubeseal CLI to encrypt a secret with the cluster's public RSA key; only that cluster (with the private key) can decrypt it. This allows developers to safely commit encrypted secrets to version control without exposing plain-text credentials. The workflow: create a Kubernetes secret YAML, encrypt it with kubeseal, commit the encrypted version to Git, and when the secret is applied to the cluster, the Sealed Secrets controller automatically decrypts it. It's transparent to applications, they read the decrypted secret as a normal K8s secret.
| 地区 | 初级 | 中级 | 高级 |
|---|---|---|---|
| USA | $85k | $135k | $190k |
| UK | $50k | $85k | $130k |
| EU | $55k | $90k | $140k |
| CANADA | $80k | $125k | $175k |
做一下职业匹配,我们会推荐合适的方向。
找到最适合我的技能 →在 2,536 个职业中进行技能匹配。免费,约 2 分钟。
免费做职业匹配 →