Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

External Secrets Operator

K8s operator that syncs secrets from external stores into Kubernetes Secrets

ToolSecrets ManagementSelf-hosted, Open source

Pricing: Free (open source)

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed April 2026 · How we review listings

What is External Secrets Operator?

External Secrets Operator (ESO) is a Kubernetes operator that syncs secrets from external stores (AWS Secrets Manager, HashiCorp Vault, GCP Secret Manager, Azure Key Vault, 1Password, and many more) into native Kubernetes Secrets. It is the de facto standard for integrating external secret backends with Kubernetes workloads, with broad community adoption and graduated CNCF status.

Best for: Kubernetes teams that want to use cloud-native or Vault secrets directly in pods

Pros

  • Massive community adoption; de facto standard for K8s + external secrets
  • Broad provider support (30+ backends)
  • Free and open source with no license cost
  • Works cleanly with GitOps workflows

Things to check

  • You still need a real secrets backend (Vault, AWS, etc.) for it to sync from
  • Operator deployment adds cluster complexity
  • No UI; all configuration is CRD-based
  • Cluster admin required to install the CRDs

Reported in public reviews and vendor documentation. See sources below.

Key Features

CustomResourceDefinition (CRD) for declarative secret syncing
Supports 30+ external secret stores
Works with AWS, Azure, GCP, HashiCorp Vault, 1Password, Doppler
Automatic secret refresh on a schedule
PushSecrets for reverse-syncing back to external stores
ClusterExternalSecret for multi-namespace syncing
Webhook provider for arbitrary external APIs
GitOps-friendly (Argo CD, Flux compatible)
Helm chart and operator deployment
CNCF Graduated project

Do you work at External Secrets Operator? to confirm the details or send us a correction.

Add the Cyber Vendor Guide badge to your site

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent External Secrets Operator? Request a correction.

Key facts

Pricing
Free (open source)
Model
Open Source
Founded
2020
Cloud
No
Self-hosted
Yes
Open source
Yes

External Secrets Operator Alternatives

  • Sealed SecretsEncrypt Kubernetes secrets into a format safe to store in Gi...
  • SOPSCLI tool for encrypting YAML/JSON/ENV files with KMS, age, o...
  • HashiCorp VaultIndustry-standard open-source secrets management platform...
  • InfisicalOpen-source end-to-end encrypted secrets management for team...
View all alternatives

Where External Secrets Operator appears

Guides

Shortlists