Automate secrets management with open-source transparency.
Centrally manage your AI Tokens, database passwords and API keys - in your Cloud Native or traditional environment
Transparent and developer-first
Without SecureGuard
- Fragmented Secrets Management
- Inconsistent Security Practices
- Vendor Lock-In and Cost
- Limited Automation and Integration
- Compliance and Audit Gaps
With SecureGuard
- Connect different secret providers into one central home
- Reduce breach risk through automation and identity-based access
- Lower costs by using open-source, self-managed infrastructure
- Eliminate manual secret rotation and synchronization
- Improve compliance with centralized auditing and detailed access logs
All you need to know about Kubermatic SecureGuard
Kubermatic SecureGuard is a self-hosted, open-source secrets management solution that acts as a secure transport layer for secrets in cloud-native and traditional environments.
KubeSG is the Kubernetes-native alternative to proprietary secrets managers. It combines the trusted security model of OpenBao with the automation power of the External Secrets Operator to enable a developer-friendly workflow. KubeSG enables automated, breakage-free secret rotation, delivering transparent, developer-friendly security for everything from infrastructure keys to AI tokens.

Why Kubermatic SecureGuard?
OpenBao Core
Secure backend with encryption in transit and at rest, fine-grained access controls, and full audit logs.
ESO Integration
Synchronize secrets directly into Kubernetes clusters or between multiple external secret stores.
Native Kubernetes Secrets Support
Developers use standard Secret objects. No app rewrites or SDKs needed.
Automated Synchronization & Rotation
Secrets stay current and valid without downtime or manual updates.
Centralized Management
One source of truth across all environments and clusters.
Secret Distribution
Deliver secrets securely to multi-cloud, edge, or disconnected environments.
Extensible Authentication & Secret Engines
Integrate easily with any identity provider or external system.
Comprehensive Auditing
Built-in visibility and compliance support for frameworks like SOC 2 and PCI-DSS.
Stolen credentials are the #1 access vector in data breaches, accounting for 22% of all incidents.
Frequently Asked Questions
What is Kubermatic SecureGuard?
Kubermatic SecureGuard (KubeSG) is Kubermatic’s secrets management solution for Kubernetes. It combines OpenBao (an open-source secrets vault) with the External Secrets Operator to sync passwords, API keys, and AI tokens directly into your clusters as standard Kubernetes secrets.
What's a good open-source alternative to HashiCorp Vault?
Since Vault moved to the Business Source License, OpenBao has become the go-to open-source fork: it’s MPL-2.0, governed by the Linux Foundation, with no BSL strings attached. However, running OpenBao at enterprise scale still takes real engineering work. Kubermatic SecureGuard (KubeSG) closes that gap. Built on OpenBao and bundled with the External Secrets Operator, it provides a Kubernetes-native secrets management platform that fits naturally into GitOps workflows, without the Business Source License (BSL) restrictions.
How do I sync secrets automatically into Kubernetes?
KubeSG uses the External Secrets Operator to sync secrets directly into your cluster as standard Kubernetes Secret objects. That means your applications don’t need any code changes or special SDKs to read them.
Can secrets rotate automatically without breaking my app?
Yes. KubeSG automates secret rotation and synchronization without requiring application rewrites or special SDKs. It updates standard Kubernetes Secrets in real time and can automatically trigger rolling updates for dependent workloads, ensuring continuous application uptime and zero-downtime credential rotation.
How do I manage AI tokens and API keys securely?
KubeSG is positioned for exactly this, centrally storing and rotating AI tokens and API keys alongside traditional secrets like database passwords, all through one system rather than scattered across tools.
What's the difference between OpenBao and HashiCorp Vault?
OpenBao is a community-governed, fully open-source fork of Vault (version 1.14), created after HashiCorp relicensed Vault under a more restrictive Business Source License. KubeSG uses OpenBao specifically to avoid that licensing restriction.



