Skip to content
BotServBotServ
Mozilla SOPSSOPSSecretsEncryptionAgePGP

Mozilla SOPS for Secrets

Encrypt secrets with Mozilla SOPS in YAML, JSON, and ENV. PGP, Age, Git integration, and AI projects.

S

schutzgeist

3 min read
Mozilla SOPS for Secrets

Mozilla SOPS for Secrets

What This Article Covers

  • What SOPS is and what it’s designed for.
  • How to use SOPS with Age or PGP.
  • How to encrypt YAML, JSON, and .env files.
  • How to integrate SOPS into Git and CI/CD.
  • Common pitfalls and best practices.

Introduction: Mozilla SOPS for Secrets

Mozilla SOPS is an open-source editor for encrypted files. It lets you encrypt YAML, JSON, .env, or binary files using PGP, Age, or cloud KMS keys. SOPS is particularly popular because it encrypts only the values and leaves the keys in plaintext. This keeps files versionable and readable.

For local AI projects, SOPS is useful for storing configuration files with API keys or database passwords securely in Git while still sharing them across your team.

Key Concepts

  • SOPS: Secrets OPerationS, a Mozilla encryption tool.
  • Age: Modern alternative to PGP, simpler and more secure.
  • PGP: Classical encryption method.
  • Master Key: Central encryption keys.
  • Data Key: The key used to encrypt actual values.
  • .sops.yaml: Configuration file for keys and encryption rules.
  • KMS: Cloud Key Management Service.

Why SOPS?

  • Only values encrypted: Keys remain readable, values do not.
  • Multiple keys: One key per file or per project.
  • Git-friendly: Version history remains usable.
  • Multiple backends: Age, PGP, AWS KMS, GCP KMS, Azure Key Vault.
  • CI/CD integration: Decryption during deployment.
  • No vendor lock-in: Open standard, self-hostable.

Installation

SOPS is available for Linux, macOS, and Windows:

wget https://github.com/getsops/sops/releases/download/v3.9.0/sops-v3.9.0.linux.amd64 -O sops
chmod +x sops
sudo mv sops /usr/local/bin/

Generating an Age Key

age-keygen -o key.txt

The key.txt file contains both the public and private key. The private key must be stored securely.

Creating Your First Encrypted File

Create a YAML file:

anthropic_api_key: DEIN_ANTHROPIC_KEY
ollama_host: http://localhost:11434

Encrypt it:

sops --age $(cat key.txt | grep "public key" | cut -d ' ' -f 3) -e -i secrets.yaml

The result is a file where values are encrypted and keys remain readable.

Decrypting and Editing

View decrypted content:

sops -d secrets.yaml

Edit the file:

sops secrets.yaml

SOPS opens your default editor, displays the decrypted values, and re-encrypts them when you save.

.sops.yaml for Automatic Rules

creation_rules:
  - path_regex: \.env\.dev$
    age: AGE_PUBLIC_KEY
  - path_regex: \.env\.prod$
    age: AGE_PUBLIC_KEY_PROD

Files are now automatically encrypted with the appropriate key.

Encrypting .env Files

sops --input-type dotenv --output-type dotenv -e .env > .env.enc

At runtime:

eval $(sops -d --output-type dotenv .env.enc)

CI/CD Integration

In a GitHub Actions workflow:

- name: Decrypt secrets
  env:
    SOPS_AGE_KEY: ${{ secrets.SOPS_AGE_KEY }}
  run: |
    sops -d secrets.yaml > secrets_decrypted.yaml

Store the private Age key as a repository secret.

SOPS vs. dotenvx and Secret Managers

  • SOPS: File-based, Git-friendly, local.
  • dotenvx: Focused on .env files, simple encryption.
  • HashiCorp Vault: Centralized management, dynamic secrets.
  • Infisical: Team secret manager with web UI.

SOPS works best for configuration files that should live in Git.

Common Pitfalls

  • Losing the private key: Values cannot be decrypted without it.
  • Specifying the wrong format: Use --input-type dotenv for .env files.
  • Committing the private key: Only public keys belong in .sops.yaml, never the private key.
  • Using the wrong key for an environment: Check your .sops.yaml rules.
  • Forgetting to update: Always save and commit after making changes.

Further Reading and Resources

FAQ: Mozilla SOPS

Is SOPS free? Yes, it is open source.

Should I use PGP or Age? For new projects, Age is simpler and more modern.

Can I use SOPS with Docker? Yes, the SOPS binary can be integrated into container images.

Who can decrypt the files? Anyone with access to a stored private key.

Are SOPS files safe in public repositories? Yes, as long as they contain only public keys and encrypted values.

Sources and Further Reading

Summary: Mozilla SOPS for Secrets

Mozilla SOPS is a powerful tool for storing configuration files with encrypted values in Git. It works especially well for .env, YAML, and JSON files in local AI projects. Age is the recommended key method for new projects. What matters is handling the private key carefully, using correct format settings, and maintaining clean .sops.yaml rules. Once you master SOPS, you have a flexible and transparent alternative to dedicated secret managers.

Back to Blog
Share:

Related Posts