Mozilla SOPS for Secrets
What This Article Covers
- What SOPS is and what it’s designed for.
- How to use SOPS with Age or PGP.
- How to encrypt YAML, JSON, and .env files.
- How to integrate SOPS into Git and CI/CD.
- Common pitfalls and best practices.
Introduction: Mozilla SOPS for Secrets
Mozilla SOPS is an open-source editor for encrypted files. It lets you encrypt YAML, JSON, .env, or binary files using PGP, Age, or cloud KMS keys. SOPS is particularly popular because it encrypts only the values and leaves the keys in plaintext. This keeps files versionable and readable.
For local AI projects, SOPS is useful for storing configuration files with API keys or database passwords securely in Git while still sharing them across your team.
Key Concepts
- SOPS: Secrets OPerationS, a Mozilla encryption tool.
- Age: Modern alternative to PGP, simpler and more secure.
- PGP: Classical encryption method.
- Master Key: Central encryption keys.
- Data Key: The key used to encrypt actual values.
- .sops.yaml: Configuration file for keys and encryption rules.
- KMS: Cloud Key Management Service.
Why SOPS?
- Only values encrypted: Keys remain readable, values do not.
- Multiple keys: One key per file or per project.
- Git-friendly: Version history remains usable.
- Multiple backends: Age, PGP, AWS KMS, GCP KMS, Azure Key Vault.
- CI/CD integration: Decryption during deployment.
- No vendor lock-in: Open standard, self-hostable.
Installation
SOPS is available for Linux, macOS, and Windows:
wget https://github.com/getsops/sops/releases/download/v3.9.0/sops-v3.9.0.linux.amd64 -O sops
chmod +x sops
sudo mv sops /usr/local/bin/
Generating an Age Key
age-keygen -o key.txt
The key.txt file contains both the public and private key. The private key must be stored securely.
Creating Your First Encrypted File
Create a YAML file:
anthropic_api_key: DEIN_ANTHROPIC_KEY
ollama_host: http://localhost:11434
Encrypt it:
sops --age $(cat key.txt | grep "public key" | cut -d ' ' -f 3) -e -i secrets.yaml
The result is a file where values are encrypted and keys remain readable.
Decrypting and Editing
View decrypted content:
sops -d secrets.yaml
Edit the file:
sops secrets.yaml
SOPS opens your default editor, displays the decrypted values, and re-encrypts them when you save.
.sops.yaml for Automatic Rules
creation_rules:
- path_regex: \.env\.dev$
age: AGE_PUBLIC_KEY
- path_regex: \.env\.prod$
age: AGE_PUBLIC_KEY_PROD
Files are now automatically encrypted with the appropriate key.
Encrypting .env Files
sops --input-type dotenv --output-type dotenv -e .env > .env.enc
At runtime:
eval $(sops -d --output-type dotenv .env.enc)
CI/CD Integration
In a GitHub Actions workflow:
- name: Decrypt secrets
env:
SOPS_AGE_KEY: ${{ secrets.SOPS_AGE_KEY }}
run: |
sops -d secrets.yaml > secrets_decrypted.yaml
Store the private Age key as a repository secret.
SOPS vs. dotenvx and Secret Managers
- SOPS: File-based, Git-friendly, local.
- dotenvx: Focused on .env files, simple encryption.
- HashiCorp Vault: Centralized management, dynamic secrets.
- Infisical: Team secret manager with web UI.
SOPS works best for configuration files that should live in Git.
Common Pitfalls
- Losing the private key: Values cannot be decrypted without it.
- Specifying the wrong format: Use
--input-type dotenvfor .env files. - Committing the private key: Only public keys belong in
.sops.yaml, never the private key. - Using the wrong key for an environment: Check your
.sops.yamlrules. - Forgetting to update: Always save and commit after making changes.
Further Reading and Resources
FAQ: Mozilla SOPS
Is SOPS free? Yes, it is open source.
Should I use PGP or Age? For new projects, Age is simpler and more modern.
Can I use SOPS with Docker? Yes, the SOPS binary can be integrated into container images.
Who can decrypt the files? Anyone with access to a stored private key.
Are SOPS files safe in public repositories? Yes, as long as they contain only public keys and encrypted values.
Sources and Further Reading
- SOPS GitHub: https://github.com/getsops/sops
- SOPS Docs: https://getsops.io/docs/
- Age: https://age-encryption.org/
Summary: Mozilla SOPS for Secrets
Mozilla SOPS is a powerful tool for storing configuration files with encrypted values in Git. It works especially well for .env, YAML, and JSON files in local AI projects. Age is the recommended key method for new projects. What matters is handling the private key carefully, using correct format settings, and maintaining clean .sops.yaml rules. Once you master SOPS, you have a flexible and transparent alternative to dedicated secret managers.


