Open-source Kubernetes-native secrets manager. Single binary, no external DB, auto-unseal by default.
-
Updated
Jul 26, 2026 - Go
Open-source Kubernetes-native secrets manager. Single binary, no external DB, auto-unseal by default.
Rotate & sync secrets across Vercel/Cloud Run/GCP SM/Koyeb/GH Actions/Atlas + local .env — values-free JSON configs, LLM-agent-safe.
Self-hosted secrets manager with REST, CLI and MCP surfaces. Encrypted at rest, per-consumer scoping, and a proxy that gives AI agents credentials without letting them hold one.
Lightweight on-premise secrets management for European enterprises. AGPL. No SaaS dependency. Air-gap compatible. NIS2/DORA aligned. AI-native via MCP server — roadmap
To associate your repository with the vault-alternative topic, visit your repo's landing page and select "manage topics."