Skip to main content

sdp-secrets-management

Stars0
Forks0
UpdatedJuly 20, 2026 at 14:28

Manage SOPS + AGE encrypted Kubernetes secrets for SURF SDP projects (instroom-config style): .sops.yaml creation rules, key management for teams, GitLab CI integration, and the decision tree for when to use Ansible Vault, SOPS+AGE, or a secret server (OpenBao/Infisical). Use this skill whenever the user encrypts or decrypts secrets, edits a *.secret.yaml or secret_orig.yaml file, hits SOPS errors ("no identity matched", "sops metadata not found", "no matching creation rules"), rotates or adds AGE keys, asks where to store a credential, or mentions sops, age, .sops.yaml, ansible-vault vs alternatives — even if they only paste a SOPS error without a question.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
4 files
SKILL.md
readonly