DevOps Practitioner · Module 3: Helm and environment configuration · Lab
Manage Environment Differences Without Secrets in the Repo
45 min hands-on · Core
A local machine with Helm installed; the demo chart plus a locally created placeholder Secret. Placeholder values only; a repo search must show zero secret bytes at the end.
Local guide: run the steps below on your own machine in order, then check the validation list.
Objectives
- Express three environment differences as layered value files
- Wire the database credential by reference with a placeholder
- Prove the repo contains no secret bytes after the work
Step 1
Layer the differences
Write base values plus dev and staging files covering replicas, host and log level. Render all three and confirm the diffs are small, named and reviewable.
Step 2
Reference the secret
Add the database Secret by reference (name only in values and manifests), create the actual placeholder Secret locally outside the repo, and render to show the reference intact with no bytes embedded.
Step 3
Prove zero bytes
Search the repo for the placeholder value and for common secret patterns, and record the clean result. Rotate the placeholder through overlap and reload to rehearse the lifecycle.
How to confirm it worked
- Three environments render from one template set with small diffs
- Secret present only as a reference; bytes live outside the repo
- Repo search shows zero secret bytes, quoted in the record
- Rotation rehearsed with traffic verified