# Encryption of secrets in yaml files

**URL:** <https://discuss.kubernetes.io/t/encryption-of-secrets-in-yaml-files/18690>\
**Category:** General Discussions\
**Created:** [January 11, 2022, 1:45pm UTC](https://discuss.kubernetes.io/t/encryption-of-secrets-in-yaml-files/18690 "2022-01-11T13:45:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![robbrown3](https://avatars.discourse-cdn.com/v4/letter/r/f6c823/32.png) [@robbrown3](https://discuss.kubernetes.io/u/robbrown3)\
**Post date:** [January 11, 2022, 1:45pm UTC](https://discuss.kubernetes.io/t/encryption-of-secrets-in-yaml-files/18690/1 "2022-01-11T13:45:04Z")

</div>

Asking for help? Comment out what you need so we can get more information to help you!

### Cluster information:

Kubernetes version:"v1.22.1  
Cloud being used: bare metal  
Installation method:  
Host OS: linux 8  
CNI and version:  
CRI and version:

I’m extremely new to kubernetes. We currently base64 encode secrets(login/password) in service-secret.yaml files. I’ve been asked to encrypt details in service-secret.yaml files.

To encrypt the details of the service-secret.yaml files, what should I do? Guidance is greatly appreciated.

---

<div class="post-metadata">

**Author:** ![Theog75](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/theog75/32/9241_2.png) [@Theog75](https://discuss.kubernetes.io/u/Theog75)\
**Post date:** [January 15, 2022, 3:16pm UTC](https://discuss.kubernetes.io/t/encryption-of-secrets-in-yaml-files/18690/2 "2022-01-15T15:16:56Z")

</div>

You can encrypt secret data at rest ([Encrypting Secret Data at Rest | Kubernetes](https://kubernetes.io/docs/tasks/administer-cluster/encrypt-data/))

But mind you,once mounted to a pod it is clear text.

---

<div class="post-metadata">

**Author:** ![Saleem\_M](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/saleem_m/32/12808_2.png) [@Saleem\_M](https://discuss.kubernetes.io/u/Saleem_M)\
**Post date:** [August 9, 2024, 11:23am UTC](https://discuss.kubernetes.io/t/encryption-of-secrets-in-yaml-files/18690/3 "2024-08-09T11:23:58Z")

</div>

Can you also please explain who does the decryption of these secrets and what keys are used for decryption in the POD
