Skip to main content

External Secrets Operator

The External Secrets Operator (ESO) copies secrets from an external store into Kubernetes Secrets and keeps them current. In the GCP Web App Blueprint it is the only way a secret reaches the application pods: values live in Secret Manager of the stage project, and the pods read plain Kubernetes Secrets the operator maintains.

What it does​

A SecretStore or cluster-wide ClusterSecretStore says where secrets come from and how to authenticate. An ExternalSecret lists the remote keys to fetch and the Kubernetes Secret to write, and a refresh interval says how often to read them again. The operator authenticates as its own identity; nothing in the cluster holds a credential for the store.

How BuiltForProd uses it​

The operator. The external-secrets unit installs chart 2.11.0 with its CRDs in the external-secrets namespace, on the tainted system pool. Its Kubernetes service account external-secrets-sa is bound through Workload Identity Federation for GKE, directly as an IAM principal, to roles/secretmanager.secretAccessor on the stage project: no Google service account and no key.

The store. The argocd unit creates the ClusterSecretStore gcp-sm for the stage project's Secret Manager, with no auth block, so the operator uses its own pod identity. It lives in a separate unit because its CRD must exist before the store can be planned.

What the chart reads. The application chart's external-secret template writes two Secrets, refreshed every hour:

Kubernetes SecretFrom
blueprint-app-secretsConnection values the infrastructure writes: mongo--uri, mongo--database, redis--host, redis--port, redis--ca, exposed as MONGO_URI, MONGO_DATABASE, REDIS_HOST, REDIS_PORT, REDIS_CA_PEM
blueprint-app-app-secretsApplication secrets <app>--<KEY> that the Secrets Blueprint syncs, for the keys listed in appSecrets.keys

The application secrets are kept encrypted in Git with SOPS in acme-gcp-blueprint-secrets and synced to Secret Manager on merge; listing a key in the stage's values file makes it an environment variable of the pods. None of the connection values is a password: the data stores authenticate with the pod's own identity.

ArgoCD. The Application ignores the ExternalSecret fields the operator's webhook fills in, so ArgoCD does not report a permanent difference.

Terms you will see​

TermMeaning
ClusterSecretStoreThe cluster-wide definition of a secret source; here gcp-sm.
ExternalSecretThe list of remote keys and the Kubernetes Secret to write.
Refresh intervalHow often the operator re-reads Secret Manager (one hour).
<app>--<KEY>The Secret Manager name of a synced application secret.

Where to read more​