{"repo":"pike00/coldkey","free":true,"listed":false,"github":"https://github.com/pike00/coldkey","clone":"git clone https://github.com/pike00/coldkey.git","description":"Post-quantum age key generation and paper backup tool with QR codes","language":"Go","stars":66,"topics":["age-encryption","cli","cryptography","disaster-recovery","docker","golang","key-management","paper-backup","post-quantum","qr-code"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"coldkey Your age encryption keys are one disk failure away from total loss. If you use age or sops to encrypt secrets, losing your private key means losing access to everything it protects -- forever. coldkey generates post-quantum (ML-KEM-768 + X25519) age keys and produces single-page printable HTML backups with QR codes. Print it, laminate it, store it in a fireproof safe. Your secrets survive even if every digital copy is gone. Quick start For defense-in-depth during key generation, see Hardened mode (Docker) below. Commands coldkey (no args) — Interactive mode Presents a menu to generate a new key or create a backup from an existing one. Prompts for file paths and confirms before overwriting. coldkey generate Generate a new post-quantum age key pair. coldkey backup Create a printable HTML paper backup from an existing key file. coldkey version Print the version string. Security model Layer Measure ------- --------- Memory mlockall(MCL CURRENT\\ MCL FUTURE) prevents key material from being swapped to disk Files Written with mode 0600 , fsynced; temporaries shredded (3-pass overwrite) Process Secrets passed via stdin/files only, never in process arguments Container --network none --read-only --cap-drop ALL --security-opt no-new-privileges:true Image distroless/static:nonroot — no shell, non-root UID 65534 Memory zeroing Best-effort secure.Zero() on key buffers before GC (see Limitations) Hardened mode (Docker) An optional distroless Docker image runs key generation under ne","default_branch":null,"files":null,"tree":[],"storefront":"/r/pike00","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/pike00/coldkey/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}