{"repo":"cyberark/secretless-broker","free":true,"listed":false,"github":"https://github.com/cyberark/secretless-broker","clone":"git clone https://github.com/cyberark/secretless-broker.git","description":"Secure your apps by making them Secretless","language":"Go","stars":384,"topics":["secret-management","proxy","golang","kubernetes","conjbot-notify","conjur-community-team"],"license":"Apache-2.0","category":"networking-infra","readme_excerpt":"Table of Contents - Secretless Broker - Supported services - Quick Start - Additional demos - Using Secretless - Using This Project With Conjur-OSS - About our releases - Community - Performance - Development - License Secretless Broker&trade; Secretless Broker is a connection broker which relieves client applications of the need to directly handle secrets to target services such as databases, web services, SSH connections, or any other TCP-based service. Secretless is designed to solve two problems. The first is loss or theft of credentials from applications and services , which can occur by: - Accidental credential leakage (e.g. credential checked into source control, etc) - An attack on a privileged user (e.g. phishing, developer machine compromises, etc) - A vulnerability in an application (e.g. remote code execution, environment variable dump, etc) The second is downtime caused when applications or services do not respond to credential rotation and crash or get locked out of target services as a result. When the client connects to a target service through the Secretless Broker: The client is not part of the threat surface The client/app no longer has direct access to the password, and therefore cannot reveal it. - The client doesn’t have to know how to properly manage secrets Handling secrets safely involves some complexities, and when every application needs to know how to handle secrets, accidents happen. The Secretless Broker centralizes the client-side management of ","default_branch":null,"files":null,"tree":[],"storefront":"/r/cyberark","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cyberark/secretless-broker/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}