# sealed-secrets GitOps source for the cluster Sealed Secrets controller. ## Current deployment - Bootstrap: `enabled: true`, applied from `main` - Argo application: `sealed-secrets-production` - Target namespace: `kube-system` - Helm chart: `bitnami-labs/sealed-secrets` - Chart version: `2.18.5` - Helm release name: `sealed-secrets-controller` ## Runtime Argo CD renders the upstream Helm chart with values from `manifest/overlays/production/helm-values/values.yaml`. The controller name is kept as `sealed-secrets-controller` so `kubeseal` works with its default controller-name assumptions. ## Secret migration workflow Fetch the controller cert with `kubeseal --fetch-cert --controller-namespace kube-system`, seal app secrets into the owning app repo, then remove old SOPS/KSOPS secret generator entries only after the app syncs from the new `SealedSecret` path.