← Back to Blog
DevSecOps & Kubernetes Published: 2026-08-11

Lightweight GitOps Secrets: Replacing HashiCorp Vault with Mozilla SOPS and Age in FluxCD

How to eliminate the operational complexity of HashiCorp Vault by encrypting GitOps secrets with Mozilla SOPS and Age keys in Kubernetes.

Anas Rhimi
Anas Rhimi August 2026 • 8 min read

Lightweight GitOps Secrets: Replacing HashiCorp Vault with Mozilla SOPS and Age in FluxCD

HashiCorp Vault is an incredible enterprise tool, but running a high-availability Vault cluster (with Raft consensus, unsealing ceremonies, and backup rotations) requires significant operational overhead. For startups and engineering teams with under 50 developers, Vault is often massive overkill.

Mozilla SOPS combined with modern Age encryption keys allows you to store encrypted Kubernetes secrets directly in Git repositories safely, enabling pure GitOps workflows without the overhead of running a dedicated secret server.

Encrypting Secrets with Age and SOPS

# 1. Generate an Age keypair
age-keygen -o age.key
# Public key: age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p

# 2. Encrypt a Kubernetes Secret YAML file
sops --encrypt --age age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p   --encrypted-regex '^(data|stringData)$'   secret.yaml > secret.enc.yaml

Frequently Asked Questions

How do Mozilla SOPS and Age work in GitOps?

SOPS encrypts secret values in YAML files using modern Age asymmetric keys, allowing encrypted secrets to be stored safely in Git and decrypted inside Kubernetes by FluxCD or ArgoCD.

Why choose SOPS over HashiCorp Vault for small teams?

SOPS requires zero servers to maintain, no unseal ceremonies, and no database backends, eliminating 90% of Vault's operational overhead.

Subscribe to the Technical Newsletter

Get deep-dives into DevOps, Kubernetes, Linux performance, and self-hosted AI architecture.

Hire Me