The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Practitioner · Module 3: Helm and environment configuration · Lab

Manage Environment Differences Without Secrets in the Repo

45 min hands-on · Core

A local machine with Helm installed; the demo chart plus a locally created placeholder Secret. Placeholder values only; a repo search must show zero secret bytes at the end.

Local guide: run the steps below on your own machine in order, then check the validation list.

Objectives

  • Express three environment differences as layered value files
  • Wire the database credential by reference with a placeholder
  • Prove the repo contains no secret bytes after the work
  1. Step 1

    Layer the differences

    Write base values plus dev and staging files covering replicas, host and log level. Render all three and confirm the diffs are small, named and reviewable.

  2. Step 2

    Reference the secret

    Add the database Secret by reference (name only in values and manifests), create the actual placeholder Secret locally outside the repo, and render to show the reference intact with no bytes embedded.

  3. Step 3

    Prove zero bytes

    Search the repo for the placeholder value and for common secret patterns, and record the clean result. Rotate the placeholder through overlap and reload to rehearse the lifecycle.

How to confirm it worked

  • Three environments render from one template set with small diffs
  • Secret present only as a reference; bytes live outside the repo
  • Repo search shows zero secret bytes, quoted in the record
  • Rotation rehearsed with traffic verified