Open source · Security

DSI Secrets Broker Apache-2.0

A sidecar that rotates secrets into running containers without a redeploy, using a KMS-backed lease per process.

Browse the catalogue

Public repository

https://github.com/dev-sec-it/secrets-broker

View repository

Releases, issues and the commit history are on the repository, so the license and the maintenance status can be checked against the last tagged release rather than taken on trust.

Catalogue record

The facts a buyer screens on first

Every value below is copied from the catalogue entry and is verifiable against the public repository.

License
Apache-2.0

OSI identifier, as published in the repository.

Stack
Go

Primary language and runtime.

Status
Production

As recorded in the DEV SEC IT catalogue.

Stars
1.4k

Counted from the public repository at the time of writing.

What we maintain

Our contribution to DSI Secrets Broker

This project is on the catalogue because we own part of it. The parts we wrote, review and release are named here; everything else is upstream work we depend on.

Maintenance

Maintained by DEV SEC IT

What we wrote

Leases, rotation backoff and the OPA policy bundle

First tagged release

First tagged release in 2023.

Where it runs

An internal dependency, not a side project.

DSI Secrets Broker is consumed inside DEV SEC IT's own platforms, which is why its release cadence and license are kept current rather than left to a final commit.

  • Consumed in production

    dCloud (Self-host or managed), dPass (Self-host or managed).

Talk to us

Need this running inside your own perimeter?

We maintain this project and the platforms built on it. If you want a deployment, a review or a fix against your environment, the same engineers who ship it can scope it.

All open source