Geheimen ManagerIntegraties

Secrets Manager Kubernetes Operator


The Bitwarden Secrets Manager Helm integration is currently in Beta status. Some features may not provide full functionality at this time.

The Bitwarden Secrets Manager Kubernetes Operator will allow teams to integrate Secrets Manager into Kubernetes workflows securely and efficiently. Using the operator, which is deployed using Helm package manager, secrets can be stored and retrieved from Secrets Manager.

Bitwarden Secrets Manager Kubernetes Operator

The sm-operator uses a controller to synchronize Bitwarden secrets into Kubernetes secrets. The operator registers the Custom Resource Definition: BitwardenSecret into the Kubernetes cluster. The cluster will listen for the newly registered BitwardenSecret, and synchronize on a configurable interval.


To get started, an active Bitwarden organization with Secrets Manager is required. Additionally, one or more access tokens associated with a machine account are required.

Additional dependencies

Add the repository to Helm

Add the Bitwarden Secrets Manager chart repository:

Plain Text
helm repo add bitwarden

Update information of locally available charts:

Plain Text
helm repo update


Create a configuration file

Create a custom values file used for deployment:

Plain Text
helm show values bitwarden/sm-operator --devel > my-values.yaml

Update configuration file

Locate my-values.yaml and fill out required values. An example can be located in the Bitwarden repository. We recommend that the following values be adjusted for your setup:


To use a different operate image version than the one included with the chart, update:

Upgrade Helm chart

Once your values.yaml file has been configured, upgrade the release to a new chart by running:

Plain Text
helm upgrade sm-operator bitwarden/sm-operator -i --debug -n sm-operator-system --create-namespace --values my-values.yaml --devel

This command installs or upgrades a release with the name sm-operator, in the namespace sm-operator-system, with the values from my-values.yaml.


To see information for the helm install or helm upgrade commands, run helm install --help or helm upgrade --help.

Create Bitwarden secrets

To synchronize secrets stored in Bitwarden Secrets Manager into Kubernetes secrets, we must create a BitwardenSecret object.

  1. Create a Kubernetes secret to authenticate with Secrets Manager:

    Plain Text
    kubectl create secret generic bw-auth-token -n <YOUR_NAMESPACE> --from-literal=token="<TOKEN_HERE>"

    This command is recorded in your shell history. To avoid exposing access token data, consider deploying with an ephemeral pipeline agent.

Deploy BitwardenSecret

The BitwardenSecret object is the synchronization setting that will be used by the operator to create and synchronize a Kubernetes secret. The Kubernetes secret belongs to a namespace and will be injected with the data that the Secrets Manager machine account has access to.

Example BitwardenSecret deployment with custom mapping:

Plain Text
cat <<EOF | kubectl apply -n <YOUR_NAMESPACE> -f - apiVersion: kind: BitwardenSecret metadata: labels: bitwardensecret bitwardensecret-sample sm-operator kustomize sm-operator name: bitwardensecret-sample spec: organizationId: "a08a8157-129e-4002-bab4-b118014ca9c7" secretName: bw-sample-secret map: - bwSecretId: 6c230265-d472-45f7-b763-b11b01023ca6 secretKeyName: test__secret__1 - bwSecretId: d132a5ed-12bd-49af-9b74-b11b01025d58 secretKeyName: test__secret__2 authToken: secretName: bw-auth-token secretKey: token EOF

In the BitwardenSecret deployment example, the custom map element is optional.