Files
wbsong111 09d0d4e59d secrets-operator v0.10.33 → 0.11.8 (#59)
* chart_version_detector: repo가 이미 등록돼 있으면 update를 건너뛰던 버그를 고친다

repo alias가 이미 helm repo list에 있으면 add/update를 통째로 건너뛰어, 로컬에
예전에 캐시된 index.yaml을 그대로 썼다 — latest_version이 조용히 낡은 값으로
나온다(실측: secrets-operator에서 실제 최신 0.11.8 대신 0.11.4가 나왔다). repo
등록 여부와 무관하게 update는 항상 호출하도록 고친다.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* secrets-operator v0.10.33 → 0.11.8

호환성: breaking_change_check 결과 breaking=false(이 차트는 custom-values.yaml이
없어 오버라이드 충돌 자체가 불가능). CVE: infisical/kubernetes-operator 이미지를
trivy+CoverageProbe로 실측한 결과 실효 HIGH 차단이 34→10건으로 줄었다(CRITICAL은
둘 다 0, 둘 다 CoverageProbe: ok로 측정 신뢰 가능). 신규 CRD 3개
(InfisicalAuth·InfisicalConnection·InfisicalStaticSecret) 추가 — 상세는
CUSTOM-README.md.

기존 v0.10.33 디렉토리는 카탈로그 정책대로 동결 보관한다(삭제하지 않음).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* secrets-operator 자체 빌드 이미지 배포 테스트 오버라이드 추가

dev 클러스터에서 hardened-containers 자체 빌드 이미지(v0.11.8-security-hardened)로
실제 업그레이드·CRD 적용·Infisical 시크릿 동기화까지 검증할 때 쓴 오버라이드.
카탈로그 값(이 차트는 애초에 custom-values.yaml 없음)은 건드리지 않는다.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 09:13:57 +09:00

3.0 KiB

Infisical Helm Chart

This is the Infisical Secrets Operator Helm chart. Find the integration documentation here

Installation

To install the chart, run the following :

# Add the Infisical repository
helm repo add infisical 'https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/' && helm repo update

# Install Infisical Secrets Operator (with default values)
helm upgrade --install --atomic \
  -n infisical-dev --create-namespace \
  infisical-secrets-operator infisical/secrets-operator

# Install Infisical Secrets Operator (with custom inline values, replace with your own values)
helm upgrade --install --atomic \
  -n infisical-dev --create-namespace \
  --set controllerManager.replicas=3 \
  infisical-secrets-operator infisical/secrets-operator

# Install Infisical Secrets Operator (with custom values file, replace with your own values file)
helm upgrade --install --atomic \
  -n infisical-dev --create-namespace \
  -f custom-values.yaml \
  infisical-secrets-operator infisical/secrets-operator

Synchronization

To sync your secrets from Infisical (or from your own instance), create the below resources :

# Create the tokenSecretReference (replace with your own token)
kubectl create secret generic infisical-example-service-token \
  --from-literal=infisicalToken="<infisical-token-here>"

# Create the InfisicalSecret
cat <<EOF | kubectl apply -f -
apiVersion: secrets.infisical.com/v1alpha1
kind: InfisicalSecret
metadata:
  # Name of of this InfisicalSecret resource
  name: infisicalsecret-example
spec:
  # The host that should be used to pull secrets from. The default value is https://app.infisical.com/api.
  hostAPI: https://app.infisical.com/api

  # The Kubernetes secret the stores the Infisical token
  tokenSecretReference:
    # Kubernetes secret name
    secretName: infisical-example-service-token
    # The secret namespace
    secretNamespace: default

  # The Kubernetes secret that Infisical Operator will create and populate with secrets from the above project
  managedSecretReference:
    # The name of managed Kubernetes secret that should be created
    secretName: infisical-managed-secret
    # The namespace the managed secret should be installed in
    secretNamespace: default
EOF

Managed secrets

Methods

To use the above created manage secrets, you can use the below methods :

  • env
  • envFrom
  • volumes

Check the docs to learn more about their implementation within your k8s resources

Auto-reload

And if you want to auto-reload your deployments, add this annotation where the managed secret is consumed :

annotations:
  secrets.infisical.com/auto-reload: "true"

Parameters

Coming soon

Local development

Coming soon

Upgrading

0.1.2

Latest stable version, no breaking changes