Skip to content
Almanac

Cipherchest

Secrets management for homelab and small-team infrastructure

Logged
22 SEP 2025
Outbound
517
Bearing
example.com

Cipherchest stores API keys, tokens and certificates behind access policies and audit logs, and hands them to services at runtime — so secrets stop living in env files and git history.

Worth knowing before you commit:

  • Dynamic, short-lived credentials beat long-lived ones where supported.
  • The audit log answers "what read this secret, when".
  • Unsealing procedures need documenting before you need them.

Adult secrets hygiene, sized for infrastructure smaller than a datacenter.

Nearby in Auth & Security

Lockship

1.8k ↗

Self-hosted identity provider: SSO, MFA and user lifecycle in one place

Auth & SecurityDockerSSO

Gatelatch

1.2k ↗

Login portal and 2FA gate for apps that never had accounts

Auth & SecurityDockerProxy