vault-k8s VS kubernetes-external-secrets

Compare vault-k8s vs kubernetes-external-secrets and see what are their differences.


First-class support for Vault and Kubernetes. (by hashicorp)


Integrate external secret management systems with Kubernetes (by external-secrets)
Our great sponsors
  • InfluxDB - Collect and Analyze Billions of Data Points in Real Time
  • Mergify - Tired of breaking your main and manually rebasing outdated pull requests?
  • SonarQube - Static code analysis for 29 languages.
vault-k8s kubernetes-external-secrets
5 26
732 2,584
1.6% -
0.0 7.7
11 days ago over 1 year ago
Go JavaScript
Mozilla Public License 2.0 MIT License
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.


Posts with mentions or reviews of vault-k8s. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-01-18.
  • GitOps and Kubernetes – Secure Handling of Secrets
    7 projects | | 18 Jan 2023
    Hashicorp Vault k8s is an operator that modifies pods via a mutating webhook to connect between vault and pod via sidecars (additional containers) to provide secrets. This has the major advantage that no secret objects are created in Kubernetes here. The disadvantage is that this way only works with Vault.
  • Solving ArgoCD Secret Management with the argocd-vault-plugin
    2 projects | /r/kubernetes | 6 Feb 2021
    They’ve made it so you can define the order that the vault sidecar starts in, so that the proxy will be running first.


Posts with mentions or reviews of kubernetes-external-secrets. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-08-13.

What are some alternatives?

When comparing vault-k8s and kubernetes-external-secrets you can also consider the following projects:

argocd-vault-plugin - An Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets

sealed-secrets - A Kubernetes controller and tool for one-way encrypted Secrets

vault-secrets-operator - Create Kubernetes secrets from Vault for a secure GitOps based workflow.

Bitwarden - The core infrastructure backend (API, database, Docker, etc).

secrets-store-csi-driver - Secrets Store CSI driver for Kubernetes secrets - Integrates secrets stores with Kubernetes via a CSI volume.

Reloader - A Kubernetes controller to watch changes in ConfigMap and Secrets and do rolling upgrades on Pods with their associated Deployment, StatefulSet, DaemonSet and DeploymentConfig – [✩Star] if you're using it!

sops-secrets-operator - Kubernetes SOPS secrets operator

bank-vaults - A Vault swiss-army knife: A CLI tool to init, unseal and configure Vault (auth methods, secret engines).


Flux - Successor:

sops - Simple and flexible tool for managing secrets

atlantis - Terraform Pull Request Automation