sealed-secrets
Chart · Security & supply chain · standard · v0.0.1
Sealed Secrets, the controller that lets you commit encrypted secrets to Git safely. A cluster-side private key decrypts SealedSecret resources into ordinary Kubernetes Secrets, so the encrypted form is the only thing that ever leaves the cluster.
Deployed image digest
sha256:7e2522cfc9ed4f82ffd15037afe2055c029e4bbfc9eb2c54e09850e83e957d47Chart OCI version
oci://ghcr.io/quenchworks/charts/sealed-secrets:0.0.1The chart pins its image by this signed digest, so you never track it yourself. Signatures, SBOM, and provenance attach to the same digest.
Security report (Trivy)
Security report (Trivy) · image sealed-secrets 0.38.4
Install the chart
Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.
Install (latest)
helm install my-sealed-secrets oci://ghcr.io/quenchworks/charts/sealed-secrets --version 0.0.1Deploys image (digest-pinned)
ghcr.io/quenchworks/images/sealed-secrets@sha256:7e2522cfc9ed4f82ffd15037afe2055c029e4bbfc9eb2c54e09850e83e957d47- Chart version
- 0.0.1
- App version
- 0.38.4
- Chart license
- Apache-2.0
- App license
- Apache-2.0
- Service port
- 8080
- Signed
- cosign (keyless)
- Values schema
- yes
- Last published
- 2026-07-26
Verify the chart
cosign verify ghcr.io/quenchworks/charts/sealed-secrets:0.0.1 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comTransparency
The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.
Upstream project: https://sealed-secrets.netlify.app