如何在Helm values.yaml文件与Helm Charts中隐藏密码及密钥?
Hey there! When working with Helm Charts, keeping sensitive data like passwords and API keys out of your values.yaml (and version control) is critical—here are the most practical, production-proven methods I’ve relied on over the years:
The most straightforward approach is to leverage Kubernetes’ built-in Secret resources instead of stuffing secrets into your values.yaml.
First, create a standalone Secret manifest (e.g., secrets.yaml):
apiVersion: v1 kind: Secret metadata: name: my-app-secrets type: Opaque data: # Remember to encode your plaintext secrets with base64 first! db-password: c3VwZXJzZWNyZXQ= api-key: dG9wc2VjcmV0
Then, reference this Secret in your Helm templates (e.g., in templates/deployment.yaml):
env: - name: DB_PASSWORD valueFrom: secretKeyRef: name: {{ .Values.secretName | default "my-app-secrets" }} key: db-password - name: API_KEY valueFrom: secretKeyRef: name: {{ .Values.secretName | default "my-app-secrets" }} key: api-key
In your values.yaml, only include a placeholder for the Secret name (no sensitive data):
secretName: my-app-secrets
You can inject secrets dynamically when running helm install or helm upgrade instead of hardcoding them.
Option A: Use --set flags
Great for quick tests or one-off deployments:
helm install my-app ./my-chart \ --set db.password=supersecret123 \ --set api.key=my-top-secret-key
Option B: Use a separate secrets values file
Create a dedicated file (e.g., secrets-values.yaml) for sensitive data, then add it to your .gitignore to avoid committing it:
# secrets-values.yaml db: password: supersecret123 api: key: my-top-secret-key
Deploy using both your base values.yaml and the secrets file:
helm install my-app ./my-chart -f values.yaml -f secrets-values.yaml
Helm lets you reference environment variables directly in your templates or values.yaml.
First, set the variables in your terminal:
export HELM_VAR_DB_PASSWORD=supersecret123 export HELM_VAR_API_KEY=my-top-secret-key
Then, reference them in your values.yaml:
db: password: {{ .Values.db.password | default (env "HELM_VAR_DB_PASSWORD") }} api: key: {{ .Values.api.key | default (env "HELM_VAR_API_KEY") }}
Or use them directly in your deployment template:
env: - name: DB_PASSWORD value: {{ env "HELM_VAR_DB_PASSWORD" }}
If you need to store secrets in version control safely, use a Helm plugin that encrypts your sensitive data:
Helm Secrets (with SOPS)
This plugin uses SOPS to encrypt secrets files, so you can commit the encrypted versions to your repo:
- Install the plugin:
helm plugin install https://github.com/jkroepke/helm-secrets - Encrypt your secrets file:
helm secrets enc secrets-values.yaml - Deploy using the encrypted file:
helm install my-app ./my-chart -f values.yaml -f secrets://secrets-values.yaml
Bitnami Sealed Secrets
This tool uses a Kubernetes controller to encrypt secrets into "SealedSecrets"—only your cluster can decrypt them. You can safely commit SealedSecret manifests to your repo without exposing sensitive data.
.gitignore No matter which method you use, always add any files containing plaintext secrets to your .gitignore:
# Helm secrets files secrets-values.yaml *.secrets.yaml # Local values overrides values.local.yaml
A quick rule of thumb: Never commit plaintext secrets to Git. Test each method to find what fits your team’s workflow and security needs best.
内容的提问来源于stack exchange,提问作者Sravan Kumar

