You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Helm values.yaml文件与Helm Charts中隐藏密码及密钥?

Hey there! When working with Helm Charts, keeping sensitive data like passwords and API keys out of your values.yaml (and version control) is critical—here are the most practical, production-proven methods I’ve relied on over the years:

1. Use Kubernetes Secrets Directly

The most straightforward approach is to leverage Kubernetes’ built-in Secret resources instead of stuffing secrets into your values.yaml.

First, create a standalone Secret manifest (e.g., secrets.yaml):

apiVersion: v1
kind: Secret
metadata:
  name: my-app-secrets
type: Opaque
data:
  # Remember to encode your plaintext secrets with base64 first!
  db-password: c3VwZXJzZWNyZXQ=
  api-key: dG9wc2VjcmV0

Then, reference this Secret in your Helm templates (e.g., in templates/deployment.yaml):

env:
  - name: DB_PASSWORD
    valueFrom:
      secretKeyRef:
        name: {{ .Values.secretName | default "my-app-secrets" }}
        key: db-password
  - name: API_KEY
    valueFrom:
      secretKeyRef:
        name: {{ .Values.secretName | default "my-app-secrets" }}
        key: api-key

In your values.yaml, only include a placeholder for the Secret name (no sensitive data):

secretName: my-app-secrets
2. Pass Secrets at Install/Upgrade Time

You can inject secrets dynamically when running helm install or helm upgrade instead of hardcoding them.

Option A: Use --set flags

Great for quick tests or one-off deployments:

helm install my-app ./my-chart \
  --set db.password=supersecret123 \
  --set api.key=my-top-secret-key

Option B: Use a separate secrets values file

Create a dedicated file (e.g., secrets-values.yaml) for sensitive data, then add it to your .gitignore to avoid committing it:

# secrets-values.yaml
db:
  password: supersecret123
api:
  key: my-top-secret-key

Deploy using both your base values.yaml and the secrets file:

helm install my-app ./my-chart -f values.yaml -f secrets-values.yaml
3. Pull Secrets from Environment Variables

Helm lets you reference environment variables directly in your templates or values.yaml.

First, set the variables in your terminal:

export HELM_VAR_DB_PASSWORD=supersecret123
export HELM_VAR_API_KEY=my-top-secret-key

Then, reference them in your values.yaml:

db:
  password: {{ .Values.db.password | default (env "HELM_VAR_DB_PASSWORD") }}
api:
  key: {{ .Values.api.key | default (env "HELM_VAR_API_KEY") }}

Or use them directly in your deployment template:

env:
  - name: DB_PASSWORD
    value: {{ env "HELM_VAR_DB_PASSWORD" }}
4. Use Helm Plugins for Encrypted Secrets Management

If you need to store secrets in version control safely, use a Helm plugin that encrypts your sensitive data:

Helm Secrets (with SOPS)

This plugin uses SOPS to encrypt secrets files, so you can commit the encrypted versions to your repo:

  1. Install the plugin:
    helm plugin install https://github.com/jkroepke/helm-secrets
    
  2. Encrypt your secrets file:
    helm secrets enc secrets-values.yaml
    
  3. Deploy using the encrypted file:
    helm install my-app ./my-chart -f values.yaml -f secrets://secrets-values.yaml
    

Bitnami Sealed Secrets

This tool uses a Kubernetes controller to encrypt secrets into "SealedSecrets"—only your cluster can decrypt them. You can safely commit SealedSecret manifests to your repo without exposing sensitive data.

5. Lock Down Version Control with .gitignore

No matter which method you use, always add any files containing plaintext secrets to your .gitignore:

# Helm secrets files
secrets-values.yaml
*.secrets.yaml
# Local values overrides
values.local.yaml

A quick rule of thumb: Never commit plaintext secrets to Git. Test each method to find what fits your team’s workflow and security needs best.

内容的提问来源于stack exchange,提问作者Sravan Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 19:02:26