3 ms·
It doesn’t provide even remotely close to the same level of security as Vault because of how it’s designed with environment variables in mind. The lack of an A
by linuxdude314 4y ago
It doesn’t provide even remotely close to the same level of security as Vault because of how it’s designed with environment variables in mind.
The lack of an API means if they want to add secret injection without env vars, you will be launching a CLI command in a thread or subprocess as opposed to using a native library.
There is something to be said about creating a secret manager that is easier to use than vault, but this misses the mark in way to many areas for me to consider it a serious contender.
- vmatsiiako 4y agoYou need to give us time since we just launched and are still in public alpha :) In the coming months, we will be adding many more advanced security features that also include API.
- tony-infisical 4y agoHey there! Not sure what you mean by "lack of an API" here as well as in other parts of this thread where you allude to the CLI connecting directly to MongoDB (it would be a terrible design choice if that was the case). Infisical does have a backend API with endpoint protection that the CLI pulls secrets from (you can inspect it yourself at the repo) — It just isn't publicly documented for folks to write their own clients for (we have this on our roadmap so do look out for it). As mentioned though, Infisical is still new and in public alpha. We've put a lot of thought into security including our choice of cryptography and end-to-end encryption; there are certainly areas that can be fortified and those will be addressed. Check in on us a few months from now and we'll have something pretty compelling :)