Simple and flexible tool for managing secrets
github.com
github.com
It would help to have some explanation of what the goals and use scenarios are, and general assumptions.
The format is language/platform agnostic and we’ve releases libraries for .NET/C# and rust, as well as developed two separate CLI utilities that can create and manage the stores.
[0] https://docs.ansible.com/ansible/latest/user_guide/vault.htm...
https://github.com/mozilla/sops#48showing-diffs-in-cleartext...
If you have many secrets you'll probably still end up breaking them out into different files to minimize conflicts between multiple in-progress branches. A good place to start is keeping a secrets file per environment+service:
- sops-dev-mywebapp.yml
- sops-dev-mydb.yml
- sops-prod-mywebapp.yml
- sops-prod-mydb.ymlhttps://terragrunt.gruntwork.io/docs/reference/built-in-func...
Have you tried BlackBox?
Projects like https://github.com/StackExchange/blackbox have the benefit of using GPG group encryption. Each person has their own secret key but any one key can decrypt the file. This makes key rotation easier.
Just to throw in another one, at my company we are using git-crypt [1], and it works pretty well in our case
If you wanted to go a step further, you can even allow "chaining" of proxies, such that the path a query takes might be, in an extreme example, similar to how Tor operates:
Client -> Proxy 1 -> Proxy 2 -> Proxy 3 -> Target -> Resolver
--Anyways, this is kinda sorta interesting, I guess, but honestly I'm more excited by and looking forward to the (hopefully!) eventual adoption and roll-out of "DNS SVCB and HTTPS RRs" [0] -- one of the other I-Ds (linked in the OP) on which ODoH is built -- and I suspect many other HN'ers will be as well (although I'd happily settle for SRV RR support in browsers).
--
[0]: https://tools.ietf.org/html/draft-ietf-dnsop-svcb-https-02
I've copied it to the "Cloudflare and Apple design a new privacy-friendly internet protocol" [0] thread that it was intended for, but it's too late to delete it from this one.
--
Is it just for easier debugging, so you can see the structure of the encrypted file?
AWS_SDK_LOAD_CONFIG=1
https://github.com/mozilla/sops/issues/471#issuecomment-5036...
(and i'm sure countless other references)Generally found that setting that env var with anything mildly complicated (in go!) in terms of AWS roles helps.
Other libraries/clis/etc (in other languages) tend to transparently traverse the credentials chain for you.
I guess one could use Mozilla SOPS to create something like gopass...