Sops – An editor of encrypted files using AWS KMS and PGP
github.com
github.com
FYI the value isn't necessarily in stopping AWS from maliciously reading your data if they wanted to (though it does make that slightly more difficult too), it's knowing that your data can't be easily recovered by someone who has access to the physical hard drives it's stored on. A typical scenario would be someone who knows where old drives are disposed of once they leave the data center - presumably AWS takes measures to wipe/destroy such drives, but knowing that the underlying data is encrypted at rest is extra assurance. There's also value for people whose compliance requirements dictate data is encrypted at rest regardless of cost and whether it actually makes sense to do.
reading your Sops config during githooks allows you to ensure everything is encrypted before commit.
The only downside I have come across is that if you accidentally encrypt a file twice you essentially lose the data. obviously, this is user error but some additional protections around this would be good.
It handles encryption keys completely behind the scenes, is trivial to integrate, and provides a UI to easily manage multiple environments and access levels in one place.
There will, of course, always be a role for more DIY solutions like sops, but if your goal is to have configuration/secrets secure, organized, and available to developers and servers in as little time as possible, you may find EnvKey interesting.
- Creating a new file
- Encrypting an existing file
- Encrypt or decrypt a file in place
- Encrypting binary files
In-place encryption/decryption is a pretty useful feature, IMO.