github.com/bitnami/sealed-secrets
v0.39.1
#444 most downloaded on Go modules
bitnami/sealed-secrets
What this package is like to depend on
Last release 4 days ago
20 Aug 2026
Ships unpredictably
gaps range from 8 days to 8.2 years
Nearly every release is documented
notes for 17 of 18 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
43 releases · first in 2017
32 releases in the last 12 months
see the full history below
Release timeline
43 releases · Jun 2017 to Aug 2026Releases
latest 43-
v0.39.2-0.20260820085735-e27ce45b162620 Aug 2026 pre-releaseNothing published for this version
-
v0.39.120 Aug 2026 -
v0.39.1-0.20260819105146-74d25c0d05ae19 Aug 2026 pre-releaseNothing published for this version
-
v0.39.1-0.20260819080030-08bbee246d7419 Aug 2026 pre-releaseNothing published for this version
-
v0.39.1-0.20260818095852-070ad1668aae18 Aug 2026 pre-releaseNothing published for this version
-
v0.39.018 Aug 2026Release notes
Open source →- [Security] fix: stop /v1/verify from acting as a decryption oracle (#2019)
- fix(controller): start HTTP early for large additional-namespaces lists (#2018)
- Rate-limit the /v1/rotate endpoint (#1971)
- test(controller): poll for server readiness instead of sleeping (#2010)
- Bump github.com/prometheus/client_golang from 1.23.2 to 1.24.1 (#2016)
- Bump k8s.io/code-generator from 0.36.2 to 0.36.3 (#2014)
- Bump github.com/mattn/go-isatty from 0.0.23 to 0.0.24 (#2011)
- Bump k8s.io/client-go from 0.36.2 to 0.36.3 (#2012)
- Bump github.com/mattn/go-isatty from 0.0.22 to 0.0.23 (#2009)
- Bump golang.org/x/crypto from 0.53.0 to 0.54.0 (#2007)
- Bump distroless/static from
3592aa8to9197324in /docker (#2008) - Allow setting hostUsers on deployment (#1978)
- Add --metrics-omit-secret-labels to skip per-SealedSecret labels on condition_info (#1972)
- Revert ArtifactHub repository metadata OCI push (#2005)
-
v0.38.5-0.20260817105023-66db186e6b3517 Aug 2026 pre-releaseNothing published for this version
-
v0.38.5-0.20260817100024-7f4a573e525017 Aug 2026 pre-releaseNothing published for this version
-
v0.38.5-0.20260817062356-1c69578c1cb017 Aug 2026 pre-releaseNothing published for this version
-
v0.38.5-0.20260811074640-0f805b98134a11 Aug 2026 pre-releaseNothing published for this version
-
v0.38.5-0.20260729101128-de72a97b196d29 Jul 2026 pre-releaseNothing published for this version
-
v0.38.5-0.20260729085440-fb7da1e9ba9829 Jul 2026 pre-releaseNothing published for this version
-
v0.38.5-0.20260722095228-15aa43988fb022 Jul 2026 pre-releaseNothing published for this version
-
v0.38.5-0.20260715105451-159d530eaf3f15 Jul 2026 pre-releaseNothing published for this version
-
v0.38.5-0.20260713075054-ce8e0726a45113 Jul 2026 pre-releaseNothing published for this version
-
v0.38.5-0.20260706071940-6a6e888bc86606 Jul 2026 pre-releaseNothing published for this version
-
v0.38.5-0.20260703130945-d6bd5908cc0503 Jul 2026 pre-releaseNothing published for this version
-
v0.38.403 Jul 2026 -
v0.38.303 Jul 2026 -
v0.38.203 Jul 2026Release notes
Open source →- Publish Artifact Hub repository metadata for verified publisher status (#2000)
- Add Artifact Hub badge to README (#1999)
- Bump github.com/onsi/ginkgo/v2 from 2.30.0 to 2.32.0 (#1998)
- Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 (#1997)
- Bump k8s.io/client-go from 0.36.1 to 0.36.2 (#1996)
- Bump k8s.io/api from 0.36.1 to 0.36.2 (#1994)
- Bump github.com/onsi/gomega from 1.41.0 to 1.42.0 (#1995)
- Bump k8s.io/code-generator from 0.36.1 to 0.36.2 (#1993)
-
v0.38.2-0.20260702134948-33b890d5f87d02 Jul 2026 pre-releaseNothing published for this version
-
v0.38.2-0.20260701063634-183e91c2fb2101 Jul 2026 pre-releaseNothing published for this version
-
v0.38.2-0.20260624122139-5e4abed9940124 Jun 2026 pre-releaseNothing published for this version
-
v0.38.2-0.20260624111036-792723c21f3524 Jun 2026 pre-releaseNothing published for this version
-
v0.38.2-0.20260618131546-20c250b253b118 Jun 2026 pre-releaseNothing published for this version
-
v0.38.118 Jun 2026 -
v0.38.018 Jun 2026Release notes
Open source →- feat: add ppc64le architecture support (#1973)
- Adding default prometheusRule in helmChart to watch out of sync secrets (#1980)
- Update security context defaults to comply with restricted pod security standard profile (#1981)
- fix: add mutex locking to KeyRegistry to prevent data races (#1905)
- Bump Golang to 1.26.4 (#1987)
- Migrate all bitnami-labs references to bitnami org (#1983)
- Change oci registry for publishing the chart (#1970)
- Revert "Fix oci push" (#1979)
- Bump golang.org/x/crypto from 0.52.0 to 0.53.0 (#1984)
- Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.30.0 (#1985)
- Bump golang.org/x/crypto from 0.51.0 to 0.52.0 (#1977)
- Bump github.com/onsi/ginkgo/v2 from 2.28.3 to 2.29.0 (#1976)
- Bump github.com/onsi/gomega from 1.40.0 to 1.41.0 (#1975)
-
v0.37.1-0.20260618094544-dc9f8fc1eb5218 Jun 2026 pre-releaseNothing published for this version
-
v0.37.1-0.20260618092210-8ba4b5b27f9818 Jun 2026 pre-releaseNothing published for this version
-
v0.37.1-0.20260617054857-fddaab34050917 Jun 2026 pre-releaseNothing published for this version
-
v0.37.1-0.20260615120210-b7f26263b03615 Jun 2026 pre-releaseNothing published for this version
-
v0.7.021 Mar 2018Release notes
Open source →Big change for this release is the switch to per-key encrypted values.
- ("Keys" as in "object key/value", not as in "encryption key". English is hard.)*
- Previously we generated a single big encrypted blob for each Secret, now we encrypt each value in the Secret separately, with the keys in plain text. This allows:
- Existing keys can now be renamed and deleted without re-encrypting the value(s).
- New keys/values can be added to the SealedSecret without re-encrypting (or even having access to!) the existing values.
- Note that (as before) the encrypted values are still tied to the namespace/name of the enclosing Secret/SealedSecret, so can't be moved to another Secret. (The cluster-wide annotation does allow this, with the corresponding caveats, as before)
- The
kubesealtool does not yet have an option to output just a single value, but you can safely mix+match the individual values fromkubesealoutput with an existing SealedSecret. Improvingkubesealsupport for this feature is still an open action item. - Existing/older "all-in-one" SealedSecrets are declared deprecated, but will continue to be supported by the controller for the foreseeable future. New invocations of the
kubesealtool now produce per-key encrypted output - if you need to produce the older format, just use an olderkubeseal. Please raise a github issue if you have a use-case that requires supporting "all-in-one" SealedSecrets going forward. - Note the CRD schema used for server-side validation in k8s >=1.9 has been temporarily removed, because it was unable to support the new per-key structure correctly (see kubernetes/kubernetes#59485).
- Huge thanks to @sullerandras for the code and his persistence in getting this merged!
-
v0.6.009 Feb 2018Release notes
Open source →- Support "cluster wide" secrets, that are not restricted to the original namespace
- Set
sealedsecrets.bitnami.com/cluster-wide: "true"annotation - Warning: cluster-wide SealedSecrets can be decrypted by anyone who can create a SealedSecret in your cluster
- Set
- Move to client-go v5.0
- Move to bitnami-labs github org
- Fix bug in schema validation for k8s 1.9
- Support "cluster wide" secrets, that are not restricted to the original namespace
-
v0.5.102 Oct 2017Release notes
Open source →Note: this version moves TPR/CRD definition into a separate file. To install, you need
controller.yamland eithersealedsecret-tpr.yamlorsealedsecret-crd.yaml- Add CRD definition and TPR->CRD migration documentation
- Add
kubeseal --fetch-certto dump server cert to stdout, for later offline use withkubeseal --cert - Better sanitization of input object to
kubeseal
(v0.5.1 fixes a travis/github release issue with v0.5.0)
-
v0.5.022 Sep 2017Nothing published for this version
-
v0.4.014 Aug 2017Release notes
Open source →- controller: deployment security hardening: non-root uid and read-only rootfs
kubeseal: Include oidc and gcp auth provider pluginskubeseal: Add support for YAML output
-
v0.3.111 Jul 2017Release notes
Open source →- Add
controller-norbac.yamlto the release build. This iscontroller.yamlwithout RBAC rules and related service account - for environments where RBAC is not yet supported, like Azure. - Fix missing controller RBAC ClusterRoleBinding in v0.3.0
- Add
-
v0.3.021 Jun 2017Release notes
Open source →Rename everything to better represent project scope. Better to do this early (now) and apologies for the disruption.
- Rename repo and golang import path ->
bitnami/sealed-secrets - Rename cli tool ->
kubeseal - Rename
SealedSecretapiGroup ->bitnami.com
- Rename repo and golang import path ->
-
v0.2.121 Jun 2017Release notes
Open source →- Fix invalid field
resourceNamein v0.2.0 controller.yaml (thanks @Globegitter)
- Fix invalid field
-
v0.2.020 Jun 2017Release notes
Open source →- Client tool has better defaults, and can fetch the certificate automatically from the controller.
- Improve release process to include pre-built Linux and OSX x86-64 binaries.
-
v0.1.008 Jun 2017 -
v0.0.105 Jun 2017Release notes
Open source →- Clean up controller.jsonnet
- Switch to quay.io (docker hub doesn't offer robot accounts??)
- Add deploy section to .travis.yml
-
v0.0.0-20260703130945-d6bd5908cc0503 Jul 2026 pre-releaseNothing published for this version