Bitnami/sealed-secrets
↗ https://github.com/bitnami/sealed-secrets
I use bitnami/sealed-secrets to deploy secrets to Kubernetes from sops.
That way I get one sops flow for both my NixOS secrets and my k8s secrets, all encrypted with age.
Lately though I've been looking at secretspec.dev instead. It supports sops as one of its backends too, so the migration shouldn't be hard.
