Sign inSign up

krishnaalagiri/ssm

By krishnaalagiri

•Updated over 4 years ago

Secure storage and delivery for tokens, passwords, API keys, and other secrets.

Image
1

1.4K

krishnaalagiri/ssm repository overview

Simple Secrets Manager

Docker Image Latest Version Docker Image Architecture GitHub Repository GitHub Repository License

Secure storage, and delivery for tokens, passwords, API keys, and other secrets using HTTP API, Swagger UI or Python Package.

TL;DR: Poor Man's Hashi Corp Vault

⁠Quick reference (cont.)

⁠Why does this exist?

Hashi Corp Vault works well but it was meant for enterprises. Therefore, it was heavy and non-portable (atleast difficult) for my homelab setup. So I wanted to build a Secrets Manager intended for small scale setups that could also scale well.

⁠Goals

  • A lightweight system that sucks less power out of the wall. Therefore, minimal background jobs and reduced resource utilizations.
  • Should be compatible on both x86-64 and arm64v8 (mainly Raspberry Pi 4).
  • High stability, availability and easy scalability.

⁠Available secret engines

Secret EngineDescription
kvKey-Value engine is used to store arbitrary secrets.

⁠Available authentication methods

Auth MethodsDescription
userpassAllows users to authenticate using a username and password combination.
tokenAllows users to authenticate using a token. Token generation requires users to be authenticated via userpass

⁠Getting started

  1. Run the stack⁠ by executing docker-compose up -d.
  2. Stop stack by executing docker-compose down
version: '3'
volumes:
  mongo_data:

services:
  # From v5.0.0, mongoDB requires atleast ARMv8.2-A microarchitecture to run.
  # So we're going with v4 to improve compatibility on SBCs such as
  # Raspberry Pi 4 and Odroid C2 with ARMv8.0-A
  mongo:
    image: mongo:4
    restart: always
    environment:
      MONGO_INITDB_ROOT_USERNAME: root
      MONGO_INITDB_ROOT_PASSWORD: password
    volumes:
      - mongo_data:/data/db
    networks:
      - app-tier

  ssm-app:
    image: krishnaalagiri/ssm:latest
    restart: always
    depends_on:
      - mongo
    ports:
      - "5000:5000"
    environment:
      CONNECTION_STRING: mongodb://root:password@mongo:27017
      PORT: 5000
    networks:
      - app-tier

networks:
  app-tier:
    driver: bridge

Tag summary

Content type

Image

Digest

Size

60.2 MB

Last updated

over 4 years ago

docker pull krishnaalagiri/ssm