Vault

Secrets under envelope encryption, with an audit log of every access.

~/cloud/vault

  • Values are encrypted at rest with envelope encryption, against a workspace key ring
  • Every access and modification is logged with the actor and the action
  • Metadata edits — name, description, category — never touch the encrypted value
  • This is where a human supplies a credential an agent asked for, without the agent ever holding it

Part of ~/cloud

See the suite →