External Secrets Operator

Also known as
external-secrets-operator

What is External Secrets Operator?

A Kubernetes operator that syncs secrets from external providers into native Kubernetes secrets.

Independently observed

External Secrets Operator pricing

We don't have External Secrets Operator's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

Pricing as of verify at live pricing ↗Independently observed
Open sourceFree tier

Open source

What External Secrets Operator does

The capabilities that matter for secrets management tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Core
Tool type
Sync / injection
Dynamic (short-lived) secrets
-
Deployment
Hosting
Self-hosted only
Lifecycle
Automatic secret rotation
-
Crypto
Encryption as a service (transit)
-
Compliance
FIPS 140-2/3 validated crypto
-
HSM support
-
Access
Fine-grained / identity-based policy
Governance
Audit logging
-
Integration
Kubernetes native (CRD / CSI / K8s auth)
Scope
PKI / certificate authority
-
Licensing
Open-source core
Ecosystem
CNCF maturity
-
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
Deployment
  • Self-hosted

Integrations (17)

Independently observed
  • AWS Secrets Manager
  • AWS Parameter Store
  • AWS Certificate Manager
  • AWS Elastic Container Registry
  • AWS STS Session Token
  • Azure Key Vault
  • Google Secrets Manager
  • Google Container Registry
  • IBM Secrets Manager
  • HashiCorp Vault
  • Yandex Lockbox
  • Gitlab Project Variables
  • Oracle Vault
  • Cloudsmith
  • Quay
  • Grafana
  • BeyondTrust

External Secrets Operator alternatives

Other secrets management tools we track, ranked by the same independent score.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for External Secrets Operator, not the verdict.

Balanced composite 63 / 100
low · 18%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Github Activity610.106.4
Release Cadence990.065.8
Capabilities580.074.0
Integrations360.072.5
Github Stars720.032.1
Security Posture00.230.0-
Package Downloads00.150.0-
Stackoverflow Activity00.070.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d84mediumsource · 2026-08-01 · 65%

Adoption

AttributeValueEvidence
Github stars6,765highsource · 2026-08-01 · 90%

Features

AttributeValueEvidence
Capabilities{"hosting":"self","tool_type":"sync_inject","open_source_core":true,"kubernetes_native":true,"fine_grained_policy":true}mediumsource · 2026-08-05 · 60%

Integrations

AttributeValueEvidence
Count17mediumsource · 2026-08-05 · 60%

Language

AttributeValueEvidence
PrimaryGohighsource · 2026-08-01 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-08-01 · 95%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-08-01 · 60%
Modelopen_sourcemediumsource · 2026-08-01 · 60%
Price levelfreemediumsource · 2026-08-01 · 60%
TransparentYesmediumsource · 2026-08-01 · 60%

Release

AttributeValueEvidence
Cadence days1mediumsource · 2026-08-01 · 70%