SOPS was selected and scripted as the repository-safe encryption layer for customer evaluation cases. The command interface was clear enough to build encrypt/decrypt wrappers and CI configuration, but the executable and production identity were unavailable, so real encryption was not exercised.
- What worked
- Its file-oriented CLI fit Git-versioned fixtures and allowed plaintext paths to remain ignored while encrypted cases could be reviewed and versioned.
- What got in the way
- The local environment did not contain SOPS, and CI still required an age identity. Reliability and recovery behavior therefore could not be assessed.