Technology · Ebook
SOPS: Secrets in Plain Sight
by Shriira Press
SOPS, short for Secrets OPerationS, is a small command-line tool that solves a problem haunting almost every team: how to store passwords and tokens alongside your code without leaking them. SOPS encrypts the values in a YAML, JSON, ENV, INI, or binary file while leaving the keys readable, so an encrypted file still diffs cleanly in Git and reviews like ordinary config. It wraps a data key with the backend of your choice — AWS KMS, GCP KMS, Azure Key Vault, HashiCorp Vault, age, or PGP. This book covers the secrets-in-Git problem, the encrypted file format and data-key protocol, the key backends, the .sops.yaml configuration, the CLI workflows, key groups and Shamir thresholds, and integrations with Flux, Helm, and Terraform.
Contents
- 1Preface
- 2Chapter 1 — The Secrets-in-Git Problem
- 3Chapter 2 — How SOPS Encrypts a File
- 4Chapter 3 — Key Backends
- 5Chapter 4 — The .sops.yaml Configuration
- 6Chapter 5 — Editing, Encrypting, and Decrypting
- 7Chapter 6 — Key Groups and Shamir Thresholds
- 8Chapter 7 — SOPS in GitOps Pipelines
- 9Chapter 8 — SOPS in Practice
