External Secrets Operator
K8s operator that syncs secrets from external stores into Kubernetes Secrets
Pricing: Free (open source)
Reviewed by the CyberSecTool editorial team against the public sources cited below · Last reviewed April 2026 · How we review listings
What is External Secrets Operator?
External Secrets Operator (ESO) is a Kubernetes operator that syncs secrets from external stores (AWS Secrets Manager, HashiCorp Vault, GCP Secret Manager, Azure Key Vault, 1Password, and many more) into native Kubernetes Secrets. It is the de facto standard for integrating external secret backends with Kubernetes workloads, with broad community adoption and graduated CNCF status.
- ✓ Massive community adoption; de facto standard for K8s + external secrets
- ✓ Broad provider support (30+ backends)
- ✓ Free and open source with no license cost
- ✓ Works cleanly with GitOps workflows
- • You still need a real secrets backend (Vault, AWS, etc.) for it to sync from
- • Operator deployment adds cluster complexity
- • No UI; all configuration is CRD-based
- • Cluster admin required to install the CRDs
Reported in public reviews and vendor documentation. See sources below.
Key Features
Are you External Secrets Operator? Improve this listing with screenshots, case studies and more.
Sources & references
Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.
Spot an error, or do you represent External Secrets Operator? Request a correction.
Quick Info
| Pricing | Free (open source) |
| Model | Open Source |
| Founded | 2020 |
| Cloud | No |
| Self-Hosted | Yes |
| Open Source | Yes |
Last updated: Apr 23, 2026
External Secrets Operator Alternatives
View All AlternativesFeaturedSplitSecureDistributed secrets management — no vault, no vendor depende...