One file · one key · nothing on disk
Every secret in one place.
API keys in dotfiles, the same token in three .env files, an SSH key that anything running as you can read. secretsthing puts every credential in one encrypted file, opened by one key you keep yourself, and hands each program its value at the moment it runs.
Act I
The sprawl.
Every tool wants its credential somewhere, and every tool picks a different somewhere. After a year, nobody knows where they all are.
01 · Where are they?
Start by finding them.
An SSH key, a GitHub token, a key for each API you pay for. Each one lives wherever its tool's setup guide said to put it.
02 · Which copy?
Then find the copies.
The same GitHub token sits in three files, because three things needed it. Rotating it means finding all three, and the one you miss keeps working until the day it doesn't.
03 · Who can read them?
Anything running as you.
Every program you start can read every one of them, including the coding agent you just gave a shell. One cat into a log or a chat transcript, and the key is somewhere else for good.
04 · A new laptop
Then you get a new laptop.
Either you copy the whole sprawl across, plaintext and all, or you reissue every credential by hand and update every file that held it.
That was one laptop.
- keys in plaintext
- 6
- copies of one token
- 3
- encrypted
- 0
- written down anywhere
- 0
Here's the same laptop, with secretsthing.
Act II
The secretsthing way.
One encrypted file holds every credential, one key opens it, and nothing is ever written to disk in the clear.
01 · One file
Every secret, once.
Every credential is a line in one file, encrypted with sops and age and kept in git. The ciphertext is safe to publish: only one key opens it.
02 · One key
One key, kept by you.
The key that opens the file lives in your password manager, and nowhere else. unlock takes it from the clipboard into memory, checks it's the right one, and forgets it when you log out.
03 · Asked for, not stored
Programs ask when they run.
A program gets its value the moment it starts, from sec, and nothing is left behind. An SSH key goes to the agent through a pipe, so it never touches a disk at all.
04 · Servers
Servers keep their own.
Each server has its own key and its own file, decrypted at boot by sops-nix into memory that only the service can read. Your key is never shipped to a box, so a lost server opens nothing else.
05 · Rotate
Rotate it in one place.
A new token is one edit to one file and a commit. The next program that asks gets the new value; there are no copies to hunt down.
Act III
How it works.
secretsthing is sops and age, wired into Nix, with two small commands in front. It does three things.
-
1
Encrypt
One file per trust group: yours, and one for each server. Files never merge, because the file is the access rule: whoever holds a file's key can read all of it.
-
2
Unlock
One key, kept by hand in a password manager, is the only secret you store. It's pasted into memory at login and checked on arrival, so a bad paste fails loudly instead of quietly.
-
3
Hand out
secgives a program its value on stdout, andsecfilea path in memory for the few that want a file. Servers do the same at boot with sops-nix.
| Question | The sprawl | secretsthing |
|---|---|---|
| Where a key lives | wherever its tool chose | one encrypted file |
| On disk in plaintext | every one of them | none |
| Rotating a token | find every copy | one edit, one commit |
| A new laptop | copy the sprawl, or reissue it | one key from your password manager |
| What a stray cat shows | the key | ciphertext |
How many key files are on your laptop?
Tell me what you run and where your credentials live today. If it fits, the first machine moves over before anything else does.