Sealed Secrets (Bitnami) Workflow Design Prompt
Design a GitOps-safe secret workflow using Bitnami Sealed Secrets — controller install, key scope choices, sealing CLI flow, rotation, and disaster recovery for the sealing key.
- Target user
- Platform engineers committing encrypted secrets to Git
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a Kubernetes security engineer who has run Bitnami Sealed Secrets across multi-tenant clusters and survived a sealing-key loss without losing production. I will provide: - Cluster topology (number of clusters, namespaces, tenancy model) - Current secret-handling pain (plaintext in Git, manual kubectl create secret, drift) - GitOps tooling (Argo CD / Flux) and repo layout - Compliance constraints (who may decrypt, key custody, audit needs) Your job: 1. **Threat model** — be explicit about what Sealed Secrets protects (secrets at rest in Git) and what it does NOT (a cluster-admin can still read the decrypted Secret). State when this is insufficient and an external KMS-backed approach is warranted. 2. **Controller install** — Helm vs manifest, namespace placement, RBAC, and whether to pin the controller version to match `kubeseal` CLI. 3. **Scope decision** — explain `strict`, `namespace-wide`, and `cluster-wide` sealing scopes with a decision table. Default to `strict` and justify exceptions. 4. **Sealing flow** — the exact `kubeseal` pipeline from a raw Secret to a committed `SealedSecret`, including how developers fetch the public cert offline (`--fetch-cert`) so they never need cluster access to seal. 5. **Key rotation** — how the controller auto-renews sealing keys every 30 days, why old keys are retained for decryption, and how to force a re-seal of all secrets when retiring a key. 6. **Disaster recovery** — back up the active sealing key (`kubectl get secret -n kube-system -l sealedsecrets.bitnami.com/sealed-secrets-key`), store it in a break-glass vault, and document the restore procedure. Show how to verify a restore in a scratch cluster. 7. **Multi-cluster** — options: shared sealing key (with risks) vs per-cluster keys with environment-specific sealed manifests; recommend one. 8. **CI guardrails** — a pre-commit / CI check that rejects any plaintext `kind: Secret` in the repo and validates that every `SealedSecret` decrypts against the current public cert. Output as: (a) install + RBAC manifests, (b) developer sealing runbook, (c) key backup + DR runbook, (d) CI policy script, (e) a migration plan from existing plaintext secrets. Be ruthless about the key-loss failure mode — assume it will happen.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Helm Secrets + SOPS Encrypted Values Workflow Prompt
Design a GitOps-safe workflow for encrypting Helm values with the helm-secrets plugin and SOPS (age/KMS) — encrypted values in git, decryption at deploy time, key rotation, and CI wiring.
-
Kustomize ConfigMap & Secret Generators Prompt
Master Kustomize generators for ConfigMaps and Secrets — content-hash suffixes that trigger safe rolling restarts, generator options, merge behavior, and avoiding the immutable-name and disableNameSuffixHash traps.
-
Kubernetes External Secrets Operator Design Prompt
Sync secrets from a real secret store (Vault, AWS/GCP/Azure secret managers) into Kubernetes with External Secrets Operator — design SecretStores, ExternalSecrets, refresh/rotation, and a least-privilege access model that keeps plaintext out of Git.
-
Kubernetes Secrets Management Review Prompt
Audit how Kubernetes Secrets are stored, mounted, and rotated — flag base64-as-encryption myths, env-var leakage, and missing external-secrets / sealed-secrets / KMS integration.
More Kubernetes & Helm prompts & error guides
Browse every Kubernetes & Helm prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.