Set up Vault (or something like it) #15

Open
opened 2026-01-07 09:55:25 +00:00 by tom · 5 comments
Owner

Could run alongside #11 - it's feeling like some kind of secret store would make life far less annoying.

Could run alongside #11 - it's feeling like some kind of secret store would make life far less annoying.
Owner

Yeah, I did wonder. The other approach might be a tiny gitolite instance with sops or pass? Or go mad and try something like https://foks.pub? :)

Yeah, I did wonder. The other approach might be a tiny gitolite instance with sops or [pass](https://www.passwordstore.org)? Or go mad and try something like https://foks.pub? :)
Author
Owner

Hmm - could work too. TBH, the main thing Vault gives over "encrypted foo in git" is the concept of TTLs so you can automate rotation.

Hmm - could work too. TBH, the main thing Vault gives over "encrypted foo in git" is the concept of TTLs so you can automate rotation.
Author
Owner

https://openbao.org/ appears to be open-source Vault.

https://openbao.org/ appears to be open-source Vault.
Owner

"But we have vault at home!" The vault at home: https://forge.deathbycomputers.co.uk/spoons.technology/secrets.git

"But we have vault at home!" The vault at home: https://forge.deathbycomputers.co.uk/spoons.technology/secrets.git
Author
Owner

"Close enough for government work"

"Close enough for government work"
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
spoons.technology/core-infra#15
No description provided.