R.E.C.R.E.C. rec.farm
Valtr

Open source · MIT · Beta

Self-hosted secrets for your apps.

Per-environment secrets encrypted at rest, API keys scoped to one project, .env and JSON exports, and an audit log. One Rust binary and one SQLite file.

Status
Beta
Version
v0.1.0
License
MIT
Built with
Rust · Axum · SQLite · AES-256-GCM

What you get

Features

  • Encrypted at restEvery value sealed with AES-256-GCM under your master key. Listings never show values.
  • Secret historyEvery write is a new version. Old values stay encrypted and can be restored.
  • Scoped API keysRead-only or read-write keys for one project that can expire and be rotated. Only their hash is stored.
  • A CLI for CI and serversStart a process with its secrets, or pull an environment as .env or JSON.
  • Audit logEvery read, write, export and deletion, with who and from where.
  • Sign in with HandstampNo passwords. Invite people to a project with a one-time link. API keys for machines.

Run it yourself

Get started

Quickstart

Clone rec-farm/valtr, then:

$ cp .env.example .env    # set VALTR_MASTER_KEY and OIDC_*
$ docker compose up -d --build