Do not create public issues. Email etty.sekhon@gmail.com.
Response: 48h acknowledgment, 7d status update.
| Tool | Purpose |
|---|---|
| Gitleaks | Secret detection (blocks PR) |
| Trivy | Config vulnerability scan → GitHub Security tab |
| Pluto | Deprecated K8s API detection |
- WIF: Workload Identity Federation (OIDC tokens, no service account keys)
- TLS: cert-manager with Let's Encrypt
- Never committed —
existingSecretpattern in Helm values - Created via
kubectl create secretor external secret operator - Pre-commit hooks detect secrets and private keys before push