7 ms·
Fnox, a secret manager that pairs well with mise
- mackross 1y agoLove the thought put into mise and now fnox. They’re a joy to use.
- maccard 1y agoAgree on mise. It's a great tool, really well implemented and easy to use. I've been trying to set up hk[0] this week and it's unfortunately not been as smooth a ride though. [0] https://hk.jdx.dev/ https://hk.jdx.dev/
- jdxcode 1y agothat's fair. The DX of hk is a much harder problem since it will always require a decent amount of customization to fit into a project. I will be improving this though. I'd probably say hk is the most challenging pre-commit manager to setup compared to its peers. That said, it's also the only one that can run hooks in parallel safely and deal with partially staged files where the others don't bother with these problems. At least right now hk is good for folks that want the fastest and don't mind a bit of effort. Hopefully I can improve that and make it the best all-around.
- maccard 1y agoIm very open to a bit of a learning curve! I wasn’t able to get a pre commit of ‘tofu fmt -check’ with the list of tf files changed working, which was frustrating! I found working with pkl tough as there’s little/no editor support (compared to writing tasks in toml with mise). I tried adding a post install hook to mise to run hk install which had surprising side effects! I’m looking forward to trying fnox!
- jdxcode 11mo agoI added this for the next hk release: https://github.com/jdx/hk/commit/0fe8610fbe5d9f1c6977e0be5963af5e28e6b639 https://github.com/jdx/hk/commit/0fe8610fbe5d9f1c6977e0be596...
- maccard 11mo agoIn the spirit of things I sent a PR in for the other footgun that I noticed. https://github.com/jdx/hk/pull/382 https://github.com/jdx/hk/pull/382
- jdxcode 11mo agoI suspect it may have been that it was using `*.tf` instead of `**/*.tf`
- drcongo 1y agoMind if I ask what trouble you've had setting up hk? I've been using it a while now and I love it almost as much as I love mise. Took me a little while to get my head around pkl (and if I'm honest, I'm very much still winging it) but otherwise it's been a joy to use.
- maccard 1y agoNo support for opentofu, so I had to write a custom hook for tofu instead of terraform. Then the hook itself didn’t work because tofu fmt didn’t like the full list of files being passed on instead of just the tf files. Then I had an issue with tflint. It wasn’t clear that hk would install in the current directory and not the git repo. Writing pkl was awkward - vscode has no support. That’s just off the top of my head.
- drcongo 1y agoThanks, that's a list of things I've never needed from it which explains our different experiences!
- maccard 11mo agoOur use case is a dotnet project with infra defined in terraform. Dotnet fmt is too slow to run as a pre commit hook so I wanted to try tflint and tofu fmt as I know they are very quick and they are relatively easy to work with. They both accept a list of files to work on, but the filter on hk gives you a full list of files that changed, so if a cs file and a tf file changes, both steps will fire with both the cs and the tf file I think a small improvement might be adding a matched_files template sub that would only show the files that matched the glob rule. I also think an LSP integration for VSCode would go a long way. I could manage the first but the second might be pushing my limits
- jdxcode 11mo agothere is one: https://github.com/apple/pkl-lsp https://github.com/apple/pkl-lsp it works great for me
- antimius 1y agoYeah, I found the import of existing pre-commit config wasn't very useful. I just switched to using prek as a much faster drop-in replacement for pre-commit https://github.com/j178/prek https://github.com/j178/prek. Really like mise though, and just started using fnox yesterday.
- cultureulterior 1y agoThere's no explanation or link to mise from that page that I can see. I now know what mise is, but that's from googling
- cultureulterior 1y agoIt's a dev tool manager
- fishgoesblub 1y agoThe link in the post is literally on the Mise Github page. One click and you're on the main page reading the detailed README.
- hackernewscunts 1y ago[dead]
- danw1979 1y agogithub.com is a popular website that lets you publish your git (a version control system) -based projects for others to read and contribute to. In this case, the user “jdx” has published an issue (a bug or feature development tracker) about a complimentary project, but you can still access the source code and documentation about “mise” by clicking on the hyperlink labelled “mise” at the top of the page.
- NamlchakKhandro 1y agolmao wut?
- domenkozar 1y ago[flagged]
- kstrauser 1y agoHow do you figure? I'm not involved with either project, but to my outsider eyes it seems like two completely different implementations of the same basic idea, with configuration that only looks necessarily similar to (i.e. there are only so many ways to write "here's how to look for secrets in 1Password" using TOML, which is a common configuration language and also one heavily used in the Rust ecosystem). Also, devenv and mise also feel like different animals to me. I can't imagine many scenarios where I'd use them interchangeably.
- domenkozar 1y agoLook at the problem statement, it's exactly the same. When I designed secretspec, I researched the space and no other tool approached secrets in such a way. Syntax of toml is almost identical, the CLI as well. It even has the same vocabulary. I didn't dig deeper though, but I'd be surprised not to find more :)
- kstrauser 1y agoI almost feel like we're looking at different things. From secretspec[0]: [project] name = "web-api" revision = "2.1.0" extends = ["../shared/base", "../shared/auth"] [profiles.default] # Inherits DATABASE_URL, LOG_LEVEL from base # Inherits JWT_SECRET, SESSION_SECRET from auth # Service-specific additions: STRIPE_API_KEY = { description = "Stripe payment API", required = true } REDIS_URL = { description = "Redis cache connection", required = true } PORT = { description = "Server port", required = false, default = "3000" } From fnox[1]: [secrets.DATABASE_URL] provider = "onepass" value = "Database" # ← Item name in 1Password (fetches 'password' field) [secrets.DB_USERNAME] provider = "onepass" value = "Database/username" # ← Specific field [secrets.API_KEY] provider = "onepass" value = "op://Development/API Keys/credential" # ← Is the similarity that they both refer to providers (as did Terraform and countless other config tools before it)? Or profiles (like aws-cli and countless other config tools before it)? Because other than that, I'm not really seeing it. And if I hadn't seen either of these, and my boss ordered me to implement something like them, I almost guarantee I'd use similar names for things because those are the common terms for them in industry. Honestly, I'm not invested in either of these. They both look nifty, but I couldn't personally care less if either (or both or neither) of these catch on and become standards. I'm only commenting here because your statement here and on the linked discussion[2] ("it's almost a verbatim copy") seems incredibly aggressive, and to me, quite offputting. They don't look alike at all to me, other than that they both aim to do similar things and thus will have some natural overlap in terminology. [0]https://secretspec.dev/concepts/declarative/ https://secretspec.dev/concepts/declarative/ [1]https://github.com/jdx/fnox https://github.com/jdx/fnox [2]https://github.com/jdx/mise/discussions/6779#discussioncomment-14796752 https://github.com/jdx/mise/discussions/6779#discussioncomme...
- augunrik 1y agoFrom the initial feature set it sounds like Mozilla SOPS.
- cippaciong 1y agoI was gonna say the same. Not that there is anything bad in having alternatives, but if you like fnox, you might want to have a look at SOPS as well.
- KingMob 1y agoMise already supported sops and age (https://mise.jdx.dev/environments/secrets/ https://mise.jdx.dev/environments/secrets/), so I'm assuming there's something more to it. (Existing or planned.)
- azazel75 1y ago[flagged]
- yoavm 1y agomise.jdx.dev/
- cjp 1y agohttps://github.com/jdx/mise https://github.com/jdx/mise It's a generic version manager (replacing nvm/pyenv/etc). It also does direnv and tasks.
- deleted 1y ago[deleted]
- NamlchakKhandro 1y agoclick the link.
- pprotas 1y agoAny alternatives to mise with less bloat? I don’t want the direnv and tasks functionality
- rsanheim 1y agoJust...don't use them? I've use mise happily for many months without using direnv or tasks, and everything I use it for works and is solid. Installs python, ruby, node, does the switching, does the shims, stays out of the way. direnv and tasks and everything else mise can do is all opt-in.
- arcanemachiner 1y agoasdf is a predecessor to mise, and focuses language version management only. https://asdf-vm.com https://asdf-vm.com
- NamlchakKhandro 1y agowhat bloat?
- Ferret7446 1y agoIf you need to manage your dev secrets, it seems like you've fucked up? It's 2025, any secrets should be generated on or provisioned on a single machine. If you're copying them or storing them, then https://xkcd.com/463/ https://xkcd.com/463/
- elric 1y agoYes, because in 2025 every business is FAANG scale and has a dedicated SRE team and a SecOps team to manage all the secrets foo. (/s, obviously) Different people have different experiences and work on things in a very diverse scale. The existence of one thing does not obviate all other things.
- 63stack 11mo agoI was about to implement it into a pilot project, but then ran into this while reading the docs: # New person joins the team: # 7. Team lead updates fnox.toml with new recipient # Then re-encrypts all secrets: fnox set DATABASE_URL "$(fnox get DATABASE_URL)" --provider age # ... repeat for all secrets It's a bit surprising you have to manually do this, I'd imagine fnox already has knowledge of all the secrets and could do this automatically.