2 ms·
Yes, I think so. In the vein of simplicity, we created a lightweight secret management script called encpass.sh (https://github.com/plyint/encpass.sh https://g
by ahnick 6y ago
Yes, I think so. In the vein of simplicity, we created a lightweight secret management script called encpass.sh (https://github.com/plyint/encpass.sh https://github.com/plyint/encpass.sh) Our use case initially was to have a simple and relatively secure way to handle secrets within shell scripts. By simple I mean does not require a lot of external dependencies and likely may already have its requirements installed on a machine.
encpass.sh only needs a POSIX compliant shell and uses OpenSSL. This is nice for restrictive computing environments (think big enterprise IT) where you may not be able to control the software that is installed on the machine.
The implementation turned out to be so useful and easily adaptable that we created an extension to it for Keybase (https://github.com/plyint/encpass.sh/blob/master/extensions/keybase/KEYBASE.md https://github.com/plyint/encpass.sh/blob/master/extensions/...) and have a whole workflow built around using the tool to manage secrets with teams and Keybase's builtin encrypted Git repos. (Primarily used in our automation scripts to hold API keys and other application level secrets)
I stop short of recommending the Keybase extension for others, since the acquisition of Keybase by Zoom, but the original OpenSSL version might prove useful for people who are looking for a simple secret management solution that is easy to plugin and extend.