I’ve always used a self-hosted Vaultwarden to manage passwords. Recently I suddenly realized the passwords in my K3s cluster were all written directly in the Git repo — neither secure nor elegant. So I decided to migrate these passwords to Bitwarden with automatic syncing to the cluster.
The whole process was actually smooth; I record the operation flow here for reference.
Why Do This
Although I use ArgoCD to publish services automatically, passwords and other sensitive information were written directly in the Git repo. This is not only insecure but also troublesome to maintain.

I wanted a controller that automatically syncs Secrets — moving passwords from Bitwarden into the K8s cluster automatically, improving security and management efficiency. Conveniently, the ArgoCD docs recommend using an independent Secrets management system, such as external-secrets.
Architecture Design
The plan is simple: deploy Bitwarden’s forwarding service and the external-secrets controller in the cluster; Secrets are automatically created into the corresponding namespaces.
For the detailed flow see: argocd bitwarden

Implementation Steps
I use ArgoCD for IaC management; below I illustrate with the Application approach.
Installing external-secrets
Install external-secrets with Helm, enabling ClusterSecretStore CRD support.
1 | apiVersion: argoproj.io/v1alpha1 |
Deploying the Bitwarden Service
Deploy the Bitwarden CLI service, ensuring passwords can be fetched normally. You can run bw list items in the container to verify.

1 | kubectl apply -f - <<EOF |
1 | # Reference docs: |
Configuring external-secrets’ Password Retrieval
Tell external-secrets how to fetch passwords from Bitwarden.
1 |
|
Auto-Syncing Passwords to the Cluster
If you’ve already saved passwords in Bitwarden, just create an ExternalSecret and the controller will sync it to the K8s cluster automatically.

1 | apiVersion: external-secrets.io/v1 |
A K8s Secret is finally generated automatically; the data has synced to the cluster and can be mounted and used directly.
1 | apiVersion: v1 |
Summary and Suggestions
I used to manage passwords with AWS SSM but never really adopted it due to cost. Now managing K8s passwords with Bitwarden is both secure and convenient. If your production environment has high security requirements, I still suggest using professional password management tools.
- Bitwarden is my self-hosted password management tool, already with automatic backup and disaster recovery, so managing cluster passwords with it is reassuring.
- Bitwarden supports permission control. If using it to manage K8s secrets, I suggest creating a separate organization for storage and using a dedicated user for reading. This way, even if the cluster is compromised, other passwords stay safe.