BlackBox Logo

BlackBox

0
Free
Visit Website

Safely store secrets in a VCS repo (i.e. Git, Mercurial, Subversion or Perforce). These commands make it easy for you to Gnu Privacy Guard (GPG) encrypt specific files in a repo so they are 'encrypted at rest' in your repository. However, the scripts make it easy to decrypt them when you need to view or edit them, and decrypt them for use in production. Originally written for Puppet, BlackBox now works with any Git or Mercurial repository. WARNING: The goal of this project is to be a simple wrapper around gpg so you and your coworkers don't have to remember its all those inscrutable and confusing flags. It is not intended to be a sophisticated encryption system that solves all problems or supports a large numbers of files. The ideal use-case is to keep secrets in a secure service such as Conjur, AWS KMS, Azure Key Vault or GCP KMS; then use Blackbox for safely storing the API keys needed to access that system. That way you are encrypting a single, tiny, file. Feature-requests for anything more will be rejected; do not expect or even request 'enterprise features'. If this disappoints you, please consider a competing project such as https://www.agwa.name/projects/git-crypt

FEATURES

ALTERNATIVES

A comprehensive resource for securing Active Directory, including attack methods and effective defenses.

Free

A secret keeper that stores secrets in DynamoDB, encrypted at rest.

Free

A PHP OAuth 2.0 authorization server implementation with support for various grants and RFCs.

Free

Zoho Vault is a secure password management tool that allows you to store and automatically fill in passwords on websites and apps.

Commercial

Identify AWS IAM permissions by brute-forcing API calls.

Free

An open-source credential management platform that provides end-to-end encrypted password sharing and storage capabilities for organizations.

Commercial

Akamai MFA is a cloud-based multi-factor authentication solution using FIDO2 standard to secure workforce logins across various applications through smartphone push notifications.

Commercial

Repokid uses Access Advisor to remove unused service permissions from IAM roles in AWS.

Free

PINNED