Why Secrets Do Not Belong in values.yaml
The risks of plaintext secrets in charts and Git.
Why Secrets Do Not Belong in values.yaml is a free DevOps Bootcamp lesson on CoddyKit. This is lesson 1 of 4. Any 3 lessons of this learning path are free to read in full — after that, CoddyKit PRO unlocks every lesson, plus hands-on practice with a built-in code editor and a 24/7 AI tutor. It is part of the DevOps Bootcamp learning path, and your progress syncs across the web and the CoddyKit app. The DevOps Bootcamp course includes 4 lessons in total.
Values Are Plain Text
A chart's values.yaml is ordinary, unencrypted text. Anything you write there, including passwords, is readable by anyone who opens the file.
Git Remembers Forever
Charts usually live in Git. A secret committed once stays in history even after you delete it, so a leak is permanent. 🔒
A Tempting Mistake
It is tempting to drop a real password straight into values.yaml to get things working. Resist it, because that value spreads everywhere.
database:
password: super-secret-123Helm Stores Release Data
On install, Helm saves the merged values into a release secret in the cluster. Your plaintext password now lives there too.
helm get values Exposes It
Anyone with release access can run helm get values and read back exactly what you passed in, plaintext password included.
helm get values myappCI Logs Leak Too
Passing secrets via --set in a pipeline often prints them to build logs, where they sit in plain view for the whole team.
helm install myapp ./chart --set db.password=secretThe Core Rule
The rule is simple: secrets must never sit in plaintext inside a chart, in Git, or on the command line. Keep them out.
Reference, Do Not Embed
The safe pattern is to reference a secret rather than embed it. Templates point to a Secret resource the cluster already holds.
valueFrom:
secretKeyRef:
name: db-credentials
key: passwordEncrypt If You Must Store
When secret values truly must live in Git, store them encrypted, so the committed file is useless without the decryption key.
Three Common Approaches
Three paths solve this: encrypting values with tools, pulling secrets from an external store, or templating Secret objects from injected data.
Encoding Is Not Security
Base64 in Kubernetes Secrets is only encoding, not encryption. It hides nothing, so never treat an encoded value as protected.
Quick Check
Why is a password in values.yaml so risky?
Recap
You saw why plaintext secrets in values.yaml leak through Git, release data, and CI logs, and why you must reference or encrypt them instead. 🎉
Learn DevOps Bootcamp with an AI tutor — free
Write and run real code in your browser, get instant help from a 24/7 AI tutor, and pick up where you left off on the web or in the app.
- Courses
- 142
- Lessons
- 568
Frequently Asked Questions
Is the “Why Secrets Do Not Belong in values.yaml” lesson free?
Yes — any 3 lessons of the DevOps Bootcamp learning path, including “Why Secrets Do Not Belong in values.yaml”, are free to read in full here on the web. After that, CoddyKit PRO unlocks every lesson, plus interactive practice with a built-in code editor and a 24/7 AI tutor. The DevOps Bootcamp course includes 4 lessons in total.
What will I learn in “Why Secrets Do Not Belong in values.yaml”?
The risks of plaintext secrets in charts and Git. You practise DevOps Bootcamp with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start DevOps Bootcamp?
No prior experience is required. DevOps Bootcamp on CoddyKit is structured for beginners through advanced learners, so you can start here or from the beginning and move at your own pace. This is lesson 1 of 4.
How long does the “Why Secrets Do Not Belong in values.yaml” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this DevOps Bootcamp lesson?
Yes. Every DevOps Bootcamp lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Why Secrets Do Not Belong in values.yaml
- Encrypting Values with helm-secrets and SOPS
- Pulling from External Secrets Operators
- Templating Kubernetes Secret Resources