Valtr
Open source · MIT · Beta
Self-hosted secrets for your apps.
Per-environment secrets encrypted at rest, API keys scoped to one project, .env and JSON exports, and an audit log. One Rust binary and one SQLite file.
- Status
- Beta
- Version
- v0.1.0
- License
- MIT
- Built with
- Rust · Axum · SQLite · AES-256-GCM
What you get
Features
- Encrypted at restEvery value sealed with AES-256-GCM under your master key. Listings never show values.
- Secret historyEvery write is a new version. Old values stay encrypted and can be restored.
- Scoped API keysRead-only or read-write keys for one project that can expire and be rotated. Only their hash is stored.
- A CLI for CI and serversStart a process with its secrets, or pull an environment as .env or JSON.
- Audit logEvery read, write, export and deletion, with who and from where.
- Sign in with HandstampNo passwords. Invite people to a project with a one-time link. API keys for machines.
Run it yourself
Get started
Quickstart
Clone rec-farm/valtr, then:
$ cp .env.example .env # set VALTR_MASTER_KEY and OIDC_*
$ docker compose up -d --build
Documentation